{"grype_matches":[{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-21441","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-21441","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-21441","date":"2026-10-08","epss":0.02922,"percentile":0.86636}],"risk":1.461,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-21441"},"relatedVulnerabilities":[{"id":"CVE-2026-21441","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-21441","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-21441","date":"2026-10-08","epss":0.02922,"percentile":0.86636}],"urls":["https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b","https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99","https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html","https://access.redhat.com/errata/RHSA-2026:0981","https://access.redhat.com/errata/RHSA-2026:0990","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:1038","https://access.redhat.com/errata/RHSA-2026:1041","https://access.redhat.com/errata/RHSA-2026:1042","https://access.redhat.com/errata/RHSA-2026:1086","https://access.redhat.com/errata/RHSA-2026:1087","https://access.redhat.com/errata/RHSA-2026:1088","https://access.redhat.com/errata/RHSA-2026:1089","https://access.redhat.com/errata/RHSA-2026:1166","https://access.redhat.com/errata/RHSA-2026:1168","https://access.redhat.com/errata/RHSA-2026:1176","https://access.redhat.com/errata/RHSA-2026:1224","https://access.redhat.com/errata/RHSA-2026:1226","https://access.redhat.com/errata/RHSA-2026:1239","https://access.redhat.com/errata/RHSA-2026:1240","https://access.redhat.com/errata/RHSA-2026:1241","https://access.redhat.com/errata/RHSA-2026:1254","https://access.redhat.com/errata/RHSA-2026:1485","https://access.redhat.com/errata/RHSA-2026:14877","https://access.redhat.com/errata/RHSA-2026:1504","https://access.redhat.com/errata/RHSA-2026:1546","https://access.redhat.com/errata/RHSA-2026:1596","https://access.redhat.com/errata/RHSA-2026:1599","https://access.redhat.com/errata/RHSA-2026:1609","https://access.redhat.com/errata/RHSA-2026:1618","https://access.redhat.com/errata/RHSA-2026:1619","https://access.redhat.com/errata/RHSA-2026:1652","https://access.redhat.com/errata/RHSA-2026:1674","https://access.redhat.com/errata/RHSA-2026:1676","https://access.redhat.com/errata/RHSA-2026:1693","https://access.redhat.com/errata/RHSA-2026:1704","https://access.redhat.com/errata/RHSA-2026:1706","https://access.redhat.com/errata/RHSA-2026:1712","https://access.redhat.com/errata/RHSA-2026:1717","https://access.redhat.com/errata/RHSA-2026:1726","https://access.redhat.com/errata/RHSA-2026:1729","https://access.redhat.com/errata/RHSA-2026:1730","https://access.redhat.com/errata/RHSA-2026:1734","https://access.redhat.com/errata/RHSA-2026:1735","https://access.redhat.com/errata/RHSA-2026:1736","https://access.redhat.com/errata/RHSA-2026:17456","https://access.redhat.com/errata/RHSA-2026:17457","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17461","https://access.redhat.com/errata/RHSA-2026:17462","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:1791","https://access.redhat.com/errata/RHSA-2026:1792","https://access.redhat.com/errata/RHSA-2026:1793","https://access.redhat.com/errata/RHSA-2026:1794","https://access.redhat.com/errata/RHSA-2026:1803","https://access.redhat.com/errata/RHSA-2026:1805","https://access.redhat.com/errata/RHSA-2026:1942","https://access.redhat.com/errata/RHSA-2026:1957","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:2106","https://access.redhat.com/errata/RHSA-2026:2126","https://access.redhat.com/errata/RHSA-2026:2137","https://access.redhat.com/errata/RHSA-2026:2139","https://access.redhat.com/errata/RHSA-2026:2144","https://access.redhat.com/errata/RHSA-2026:2256","https://access.redhat.com/errata/RHSA-2026:2456","https://access.redhat.com/errata/RHSA-2026:2500","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:2563","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2695","https://access.redhat.com/errata/RHSA-2026:2717","https://access.redhat.com/errata/RHSA-2026:2718","https://access.redhat.com/errata/RHSA-2026:2723","https://access.redhat.com/errata/RHSA-2026:2728","https://access.redhat.com/errata/RHSA-2026:2760","https://access.redhat.com/errata/RHSA-2026:2762","https://access.redhat.com/errata/RHSA-2026:2764","https://access.redhat.com/errata/RHSA-2026:2765","https://access.redhat.com/errata/RHSA-2026:28043","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:2900","https://access.redhat.com/errata/RHSA-2026:2911","https://access.redhat.com/errata/RHSA-2026:2919","https://access.redhat.com/errata/RHSA-2026:2924","https://access.redhat.com/errata/RHSA-2026:2925","https://access.redhat.com/errata/RHSA-2026:2926","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:33154","https://access.redhat.com/errata/RHSA-2026:3406","https://access.redhat.com/errata/RHSA-2026:3444","https://access.redhat.com/errata/RHSA-2026:3461","https://access.redhat.com/errata/RHSA-2026:3462","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:4185","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:4215","https://access.redhat.com/errata/RHSA-2026:4271","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:44696","https://access.redhat.com/errata/RHSA-2026:51357","https://access.redhat.com/errata/RHSA-2026:5459","https://access.redhat.com/errata/RHSA-2026:61628","https://access.redhat.com/errata/RHSA-2026:6287","https://access.redhat.com/errata/RHSA-2026:6292","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8500","https://access.redhat.com/errata/RHSA-2026:8501","https://access.redhat.com/security/cve/CVE-2026-21441","https://bugzilla.redhat.com/show_bug.cgi?id=2427726","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-21441","description":"urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"a9c1f2bbf70f37c8","cpes":["cpe:2.3:a:libjpeg-turbo8:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg-turbo8:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*"],"name":"libjpeg-turbo8","purl":"pkg:deb/ubuntu/libjpeg-turbo8@2.1.5-2ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=libjpeg-turbo","type":"deb","version":"2.1.5-2ubuntu2","language":"","licenses":["BSD-3-clause","BSD-BY-LC-NE","Expat","NTP","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjpeg-turbo8/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libjpeg-turbo8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libjpeg-turbo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-10126","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libjpeg-turbo","version":"2.1.5-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2018-10126","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10126","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"risk":0.5487,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-10126"},"relatedVulnerabilities":[{"id":"CVE-2018-10126","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-10126","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-10126","date":"2026-10-08","epss":0.01829,"percentile":0.78201}],"urls":["http://bugzilla.maptools.org/show_bug.cgi?id=2786","https://gitlab.com/libtiff/libtiff/-/issues/128","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-10126","description":"ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c."}]},{"artifact":{"id":"57ae2119a8593e71","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/ubuntu/libopenjp2-7@2.5.0-2ubuntu0.5?arch=amd64&distro=ubuntu-24.04&upstream=openjpeg2","type":"deb","version":"2.5.0-2ubuntu0.5","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6988","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openjpeg2","version":"2.5.0-2ubuntu0.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2019-6988","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"risk":0.5172,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-6988"},"relatedVulnerabilities":[{"id":"CVE-2019-6988","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6988","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-6988","date":"2026-10-08","epss":0.01724,"percentile":0.76824}],"urls":["http://www.securityfocus.com/bid/106785","https://github.com/uclouvain/openjpeg/issues/1178"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6988","description":"An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44432","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44432","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44432","date":"2026-10-08","epss":0.00882,"percentile":0.57906}],"risk":0.441,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44432"},"relatedVulnerabilities":[{"id":"CVE-2026-44432","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-44432","cwe":"CWE-409","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-44432","date":"2026-10-08","epss":0.00882,"percentile":0.57906}],"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j","https://access.redhat.com/errata/RHSA-2026:15862","https://access.redhat.com/errata/RHSA-2026:20338","https://access.redhat.com/errata/RHSA-2026:22934","https://access.redhat.com/errata/RHSA-2026:24000","https://access.redhat.com/errata/RHSA-2026:24009","https://access.redhat.com/errata/RHSA-2026:24014","https://access.redhat.com/errata/RHSA-2026:24069","https://access.redhat.com/errata/RHSA-2026:24374","https://access.redhat.com/errata/RHSA-2026:24476","https://access.redhat.com/errata/RHSA-2026:24483","https://access.redhat.com/errata/RHSA-2026:24540","https://access.redhat.com/errata/RHSA-2026:24541","https://access.redhat.com/errata/RHSA-2026:24542","https://access.redhat.com/errata/RHSA-2026:24544","https://access.redhat.com/errata/RHSA-2026:25039","https://access.redhat.com/errata/RHSA-2026:25143","https://access.redhat.com/errata/RHSA-2026:25928","https://access.redhat.com/errata/RHSA-2026:26212","https://access.redhat.com/errata/RHSA-2026:26304","https://access.redhat.com/errata/RHSA-2026:27929","https://access.redhat.com/errata/RHSA-2026:28000","https://access.redhat.com/errata/RHSA-2026:28157","https://access.redhat.com/errata/RHSA-2026:28158","https://access.redhat.com/errata/RHSA-2026:28159","https://access.redhat.com/errata/RHSA-2026:28571","https://access.redhat.com/errata/RHSA-2026:30076","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:32992","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:33683","https://access.redhat.com/errata/RHSA-2026:34160","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34526","https://access.redhat.com/errata/RHSA-2026:34531","https://access.redhat.com/errata/RHSA-2026:34533","https://access.redhat.com/errata/RHSA-2026:34607","https://access.redhat.com/errata/RHSA-2026:36350","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:51206","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:59409","https://access.redhat.com/errata/RHSA-2026:60362","https://access.redhat.com/errata/RHSA-2026:60371","https://access.redhat.com/errata/RHSA-2026:7625","https://access.redhat.com/errata/RHSA-2026:7634","https://access.redhat.com/security/cve/CVE-2026-44432","https://bugzilla.redhat.com/show_bug.cgi?id=2477154","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44432","description":"urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66418","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66418","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66418","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66418","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"risk":0.34099999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66418"},"relatedVulnerabilities":[{"id":"CVE-2025-66418","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66418","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66418","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"urls":["https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8","https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66471","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66471","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66471","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66471","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"risk":0.34099999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66471"},"relatedVulnerabilities":[{"id":"CVE-2025-66471","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66471","cwe":"CWE-409","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-66471","date":"2026-10-08","epss":0.00682,"percentile":0.50973}],"urls":["https://github.com/urllib3/urllib3/commit/c19571de34c47de3a766541b041637ba5f716ed7","https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66471","description":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"57ae2119a8593e71","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/ubuntu/libopenjp2-7@2.5.0-2ubuntu0.5?arch=amd64&distro=ubuntu-24.04&upstream=openjpeg2","type":"deb","version":"2.5.0-2ubuntu0.5","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39329","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openjpeg2","version":"2.5.0-2ubuntu0.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2023-39329","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"risk":0.294,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-39329"},"relatedVulnerabilities":[{"id":"CVE-2023-39329","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39329","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39329","date":"2026-10-08","epss":0.00588,"percentile":0.4644}],"urls":["https://access.redhat.com/errata/RHSA-2026:4128","https://access.redhat.com/security/cve/CVE-2023-39329","https://bugzilla.redhat.com/show_bug.cgi?id=2295816","https://github.com/uclouvain/openjpeg/issues/1474"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39329","description":"A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.2745,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77214"},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57585","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57585","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57585","date":"2026-10-08","epss":0.00488,"percentile":0.40034}],"risk":0.244,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57585"},"relatedVulnerabilities":[{"id":"CVE-2026-57585","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57585","cwe":"CWE-416","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57585","date":"2026-10-08","epss":0.00488,"percentile":0.40034}],"urls":["https://github.com/msgpack/msgpack-python/commit/2c56ddb5d0025ed481d962c0f5d62d19dec7476d","https://github.com/msgpack/msgpack-python/security/advisories/GHSA-6v7p-g79w-8964"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57585","description":"MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack.  If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8643","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8643","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-08","epss":0.00466,"percentile":0.38331}],"risk":0.233,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8643"},"relatedVulnerabilities":[{"id":"CVE-2026-8643","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-08","epss":0.00466,"percentile":0.38331}],"urls":["https://github.com/pypa/pip/pull/14000","https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/","http://www.openwall.com/lists/oss-security/2026/06/01/5","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34456","https://access.redhat.com/errata/RHSA-2026:34739","https://access.redhat.com/errata/RHSA-2026:34740","https://access.redhat.com/errata/RHSA-2026:34741","https://access.redhat.com/errata/RHSA-2026:34748","https://access.redhat.com/errata/RHSA-2026:34749","https://access.redhat.com/errata/RHSA-2026:34750","https://access.redhat.com/errata/RHSA-2026:34752","https://access.redhat.com/errata/RHSA-2026:34756","https://access.redhat.com/errata/RHSA-2026:34758","https://access.redhat.com/errata/RHSA-2026:34760","https://access.redhat.com/errata/RHSA-2026:34765","https://access.redhat.com/errata/RHSA-2026:34772","https://access.redhat.com/errata/RHSA-2026:34773","https://access.redhat.com/errata/RHSA-2026:34774","https://access.redhat.com/errata/RHSA-2026:34775","https://access.redhat.com/errata/RHSA-2026:34776","https://access.redhat.com/errata/RHSA-2026:34777","https://access.redhat.com/errata/RHSA-2026:34778","https://access.redhat.com/errata/RHSA-2026:34780","https://access.redhat.com/errata/RHSA-2026:34891","https://access.redhat.com/errata/RHSA-2026:36193","https://access.redhat.com/errata/RHSA-2026:36315","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37283","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:50479","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/security/cve/CVE-2026-8643","https://bugzilla.redhat.com/show_bug.cgi?id=2460927","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643","description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-45409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-45409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"risk":0.2285,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-45409"},"relatedVulnerabilities":[{"id":"CVE-2026-45409","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-45409","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-45409","date":"2026-10-08","epss":0.00457,"percentile":0.37632}],"urls":["https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-45409","description":"Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application."}]},{"artifact":{"id":"ae36307ca07e59fc","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.1\\+git230720-4ubuntu2.5:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/ubuntu/libtiff6@4.5.1%2Bgit230720-4ubuntu2.5?arch=amd64&distro=ubuntu-24.04&upstream=tiff","type":"deb","version":"4.5.1+git230720-4ubuntu2.5","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12912","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tiff","version":"4.5.1+git230720-4ubuntu2.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12912","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"risk":0.21649999999999997,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12912"},"relatedVulnerabilities":[{"id":"CVE-2026-12912","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.3,"impactScore":5.9,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-12912","cwe":"CWE-122","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-12912","date":"2026-10-08","epss":0.00433,"percentile":0.35555}],"urls":["https://access.redhat.com/errata/RHSA-2026:34890","https://access.redhat.com/errata/RHSA-2026:41892","https://access.redhat.com/errata/RHSA-2026:42668","https://access.redhat.com/errata/RHSA-2026:47183","https://access.redhat.com/errata/RHSA-2026:47184","https://access.redhat.com/errata/RHSA-2026:49671","https://access.redhat.com/errata/RHSA-2026:50774","https://access.redhat.com/errata/RHSA-2026:54638","https://access.redhat.com/errata/RHSA-2026:54640","https://access.redhat.com/errata/RHSA-2026:54642","https://access.redhat.com/errata/RHSA-2026:58545","https://access.redhat.com/errata/RHSA-2026:58553","https://access.redhat.com/errata/RHSA-2026:58554","https://access.redhat.com/errata/RHSA-2026:58556","https://access.redhat.com/errata/RHSA-2026:61657","https://access.redhat.com/errata/RHSA-2026:69292","https://access.redhat.com/errata/RHSA-2026:73909","https://access.redhat.com/errata/RHSA-2026:73959","https://access.redhat.com/errata/RHSA-2026:73960","https://access.redhat.com/errata/RHSA-2026:73961","https://access.redhat.com/errata/RHSA-2026:73962","https://access.redhat.com/errata/RHSA-2026:74458","https://access.redhat.com/errata/RHSA-2026:74459","https://access.redhat.com/errata/RHSA-2026:74460","https://access.redhat.com/errata/RHSA-2026:74461","https://access.redhat.com/errata/RHSA-2026:74462","https://access.redhat.com/errata/RHSA-2026:74463","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-12912","https://bugzilla.redhat.com/show_bug.cgi?id=2492871","https://gitlab.com/libtiff/libtiff/-/merge_requests/873","https://gitlab.com/libtiff/libtiff/-/work_items/824","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12912.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12912","description":"A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS)."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"c4efc37ba8e6101d","cpes":["cpe:2.3:a:python3-setuptools-whl:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools-whl:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_whl:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_whl:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-setuptools-whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_setuptools_whl:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*"],"name":"python3-setuptools-whl","purl":"pkg:deb/ubuntu/python3-setuptools-whl@68.1.2-2ubuntu1.2?arch=all&distro=ubuntu-24.04&upstream=setuptools","type":"deb","version":"68.1.2-2ubuntu1.2","language":"","licenses":["Apache-2.0","BSD-3-Clause","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-setuptools-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-setuptools-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-setuptools-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-setuptools-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-setuptools-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-setuptools-whl.list"}],"upstreams":[{"name":"setuptools"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59890","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"setuptools","version":"68.1.2-2ubuntu1.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-59890","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"risk":0.20249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-59890"},"relatedVulnerabilities":[{"id":"CVE-2026-59890","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"urls":["https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/setuptools/releases/tag/v83.0.0","https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f2f9ea64412a82e3","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/ubuntu/libavahi-client3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.19979999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52616"},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"e190b3f2d6ee823a","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/ubuntu/libavahi-common-data@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.19979999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52616"},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"1439f27e2c1f750c","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/ubuntu/libavahi-common3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52616","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52616","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"risk":0.19979999999999998,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52616"},"relatedVulnerabilities":[{"id":"CVE-2024-52616","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52616","cwe":"CWE-334","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52616","date":"2026-10-08","epss":0.00666,"percentile":0.50306}],"urls":["https://access.redhat.com/errata/RHSA-2025:7437","https://access.redhat.com/security/cve/CVE-2024-52616","https://bugzilla.redhat.com/show_bug.cgi?id=2326429","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52616","description":"A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87875","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87875","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87875","date":"2026-10-08","epss":0.00392,"percentile":0.31212}],"risk":0.196,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87875"},"relatedVulnerabilities":[{"id":"CVE-2026-87875","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87875","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87875","date":"2026-10-08","epss":0.00392,"percentile":0.31212}],"urls":["https://access.redhat.com/errata/RHSA-2026:66600","https://access.redhat.com/security/cve/CVE-2026-87875","https://bugzilla.redhat.com/show_bug.cgi?id=2530994","https://github.com/OpenPrinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142","https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4","https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875","description":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content."}]},{"artifact":{"id":"ae36307ca07e59fc","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.1\\+git230720-4ubuntu2.5:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/ubuntu/libtiff6@4.5.1%2Bgit230720-4ubuntu2.5?arch=amd64&distro=ubuntu-24.04&upstream=tiff","type":"deb","version":"4.5.1+git230720-4ubuntu2.5","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-4775","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tiff","version":"4.5.1+git230720-4ubuntu2.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-4775","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4775","date":"2026-10-08","epss":0.00375,"percentile":0.29323}],"risk":0.1875,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-4775"},"relatedVulnerabilities":[{"id":"CVE-2026-4775","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2026-4775","cwe":"CWE-190","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-4775","date":"2026-10-08","epss":0.00375,"percentile":0.29323}],"urls":["https://access.redhat.com/errata/RHSA-2026:12265","https://access.redhat.com/errata/RHSA-2026:12271","https://access.redhat.com/errata/RHSA-2026:14929","https://access.redhat.com/errata/RHSA-2026:16055","https://access.redhat.com/errata/RHSA-2026:19150","https://access.redhat.com/errata/RHSA-2026:19363","https://access.redhat.com/errata/RHSA-2026:19585","https://access.redhat.com/errata/RHSA-2026:19586","https://access.redhat.com/errata/RHSA-2026:19604","https://access.redhat.com/errata/RHSA-2026:19608","https://access.redhat.com/errata/RHSA-2026:19609","https://access.redhat.com/errata/RHSA-2026:19657","https://access.redhat.com/errata/RHSA-2026:19659","https://access.redhat.com/errata/RHSA-2026:19702","https://access.redhat.com/errata/RHSA-2026:20583","https://access.redhat.com/errata/RHSA-2026:20585","https://access.redhat.com/errata/RHSA-2026:20591","https://access.redhat.com/errata/RHSA-2026:20592","https://access.redhat.com/errata/RHSA-2026:24992","https://access.redhat.com/errata/RHSA-2026:25096","https://access.redhat.com/errata/RHSA-2026:25910","https://access.redhat.com/errata/RHSA-2026:30078","https://access.redhat.com/errata/RHSA-2026:30087","https://access.redhat.com/errata/RHSA-2026:30088","https://access.redhat.com/errata/RHSA-2026:30089","https://access.redhat.com/errata/RHSA-2026:30349","https://access.redhat.com/errata/RHSA-2026:33388","https://access.redhat.com/errata/RHSA-2026:74674","https://access.redhat.com/security/cve/CVE-2026-4775","https://bugzilla.redhat.com/show_bug.cgi?id=2450768","https://lists.debian.org/debian-lts-announce/2026/04/msg00016.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4775.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4775","description":"A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an out-of-bounds heap write due to incorrect memory pointer calculations, potentially causing a denial of service (application crash) or arbitrary code execution."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"a9c1f2bbf70f37c8","cpes":["cpe:2.3:a:libjpeg-turbo8:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg-turbo8:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg_turbo8:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg-turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*","cpe:2.3:a:libjpeg:libjpeg_turbo8:2.1.5-2ubuntu2:*:*:*:*:*:*:*"],"name":"libjpeg-turbo8","purl":"pkg:deb/ubuntu/libjpeg-turbo8@2.1.5-2ubuntu2?arch=amd64&distro=ubuntu-24.04&upstream=libjpeg-turbo","type":"deb","version":"2.1.5-2ubuntu2","language":"","licenses":["BSD-3-clause","BSD-BY-LC-NE","Expat","NTP","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjpeg-turbo8/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libjpeg-turbo8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libjpeg-turbo8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libjpeg-turbo"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75466","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libjpeg-turbo","version":"2.1.5-2ubuntu2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-75466","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-75466","cwe":"CWE-369","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-75466","date":"2026-10-08","epss":0.00355,"percentile":0.27117}],"risk":0.17750000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-75466"},"relatedVulnerabilities":[{"id":"CVE-2026-75466","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75466","cwe":"CWE-369","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-75466","date":"2026-10-08","epss":0.00355,"percentile":0.27117}],"urls":["https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75466","description":"libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a SIGFPE and denial of service."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.174,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102633"},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-35195","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-35195","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-35195","cwe":"CWE-670","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-35195","date":"2026-10-08","epss":0.0034,"percentile":0.25403}],"risk":0.16999999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-35195"},"relatedVulnerabilities":[{"id":"CVE-2024-35195","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":5.6,"impactScore":5.2,"exploitabilityScore":0.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-35195","cwe":"CWE-670","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2024-35195","date":"2026-10-08","epss":0.0034,"percentile":0.25403}],"urls":["https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac","https://github.com/psf/requests/pull/6655","https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IYLSNK5TL46Q6XPRVMHVWS63MVJQOK4Q/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N7WP6EYDSUOCOJYHDK5NX43PYZ4SNHGZ/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-35195","description":"Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44431","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44431","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44431","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44431","date":"2026-10-08","epss":0.00339,"percentile":0.2526}],"risk":0.16949999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44431"},"relatedVulnerabilities":[{"id":"CVE-2026-44431","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44431","cwe":"CWE-200","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44431","date":"2026-10-08","epss":0.00339,"percentile":0.2526}],"urls":["https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc","https://lists.debian.org/debian-lts-announce/2026/06/msg00040.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431","description":"urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0."}]},{"artifact":{"id":"f2f9ea64412a82e3","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/ubuntu/libavahi-client3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.1683,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52615"},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"e190b3f2d6ee823a","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/ubuntu/libavahi-common-data@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.1683,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52615"},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"1439f27e2c1f750c","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/ubuntu/libavahi-common3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-52615","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-52615","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"risk":0.1683,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-52615"},"relatedVulnerabilities":[{"id":"CVE-2024-52615","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-52615","cwe":"CWE-330","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2024-52615","date":"2026-10-08","epss":0.00561,"percentile":0.44955}],"urls":["https://access.redhat.com/errata/RHSA-2025:11402","https://access.redhat.com/errata/RHSA-2025:16441","https://access.redhat.com/security/cve/CVE-2024-52615","https://bugzilla.redhat.com/show_bug.cgi?id=2326418","https://github.com/avahi/avahi/pull/577"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-52615","description":"A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected."}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87876","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87876","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87876","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87876","date":"2026-10-08","epss":0.00328,"percentile":0.23841}],"risk":0.164,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87876"},"relatedVulnerabilities":[{"id":"CVE-2026-87876","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N","metrics":{"baseScore":3,"impactScore":1.5,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87876","cwe":"CWE-178","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-87876","date":"2026-10-08","epss":0.00328,"percentile":0.23841}],"urls":["https://access.redhat.com/errata/RHSA-2026:67568","https://access.redhat.com/security/cve/CVE-2026-87876","https://bugzilla.redhat.com/show_bug.cgi?id=2530991","https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8","https://github.com/OpenPrinting/cups/commit/f56844dbe4a54a9f8e1aeb3b913fbee614156bdb","https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87876","description":"Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-13346","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-13346"},"relatedVulnerabilities":[{"id":"CVE-2026-13346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-08","epss":0.00292,"percentile":0.19984}],"urls":["https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/","http://www.openwall.com/lists/oss-security/2026/07/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346","description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97689","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97689","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97689"},"relatedVulnerabilities":[{"id":"CVE-2026-97689","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97689","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97689","date":"2026-10-08","epss":0.00292,"percentile":0.19921}],"urls":["https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97689","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97688","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97688","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"risk":0.1455,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97688"},"relatedVulnerabilities":[{"id":"CVE-2026-97688","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97688","cwe":"CWE-835","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97688","date":"2026-10-08","epss":0.00291,"percentile":0.19899}],"urls":["https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97688","description":"urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1703","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-1703","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1703","date":"2026-10-08","epss":0.00443,"percentile":0.36495}],"risk":0.1329,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-1703"},"relatedVulnerabilities":[{"id":"CVE-2026-1703","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1703","date":"2026-10-08","epss":0.00443,"percentile":0.36495}],"urls":["https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735","https://github.com/pypa/pip/pull/13777","https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1703","description":"When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"de3f837e6f9ffb9c","cpes":["cpe:2.3:a:ghostscript:ghostscript:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"ghostscript","purl":"pkg:deb/ubuntu/ghostscript@10.02.1~dfsg1-0ubuntu7.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ghostscript/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/ghostscript/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.list"},{"path":"/var/lib/dpkg/info/ghostscript.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.postinst"},{"path":"/var/lib/dpkg/info/ghostscript.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.132,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103226"},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"534916fabd9863d8","cpes":["cpe:2.3:a:libgs-common:libgs-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"libgs-common","purl":"pkg:deb/ubuntu/libgs-common@10.02.1~dfsg1-0ubuntu7.9?arch=all&distro=ubuntu-24.04&upstream=ghostscript","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.132,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103226"},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"0db51484e969d817","cpes":["cpe:2.3:a:libgs10:libgs10:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"libgs10","purl":"pkg:deb/ubuntu/libgs10@10.02.1~dfsg1-0ubuntu7.9?arch=amd64&distro=ubuntu-24.04&upstream=ghostscript","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.132,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103226"},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"4588322eaa33fbd9","cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"libgs10-common","purl":"pkg:deb/ubuntu/libgs10-common@10.02.1~dfsg1-0ubuntu7.9?arch=all&distro=ubuntu-24.04&upstream=ghostscript","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103226","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103226","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"risk":0.132,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103226"},"relatedVulnerabilities":[{"id":"CVE-2026-103226","cvss":[{"type":"Primary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103226","cwe":"CWE-119","type":"Primary","source":"cna@vuldb.com"},{"cve":"CVE-2026-103226","cwe":"CWE-121","type":"Primary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-103226","date":"2026-10-08","epss":0.0044,"percentile":0.36233}],"urls":["https://artifex.com/","https://bugs.ghostscript.com/attachment.cgi?id=28495","https://bugs.ghostscript.com/show_bug.cgi?id=709672","https://bugs.ghostscript.com/show_bug.cgi?id=709672#c3","https://vuldb.com/cve/CVE-2026-103226","https://vuldb.com/submit/955016","https://vuldb.com/vuln/411906","https://vuldb.com/vuln/411906/cti"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103226","description":"A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. It is suggested to install a patch to address this issue. A solution was implemented: \"I've chosen to fix this slightly differently by using the defined macro in the font parsing loop rather than in the callsubr function, because this better matches the pattern of 'normal' usage.\""}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"57ae2119a8593e71","cpes":["cpe:2.3:a:libopenjp2-7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2-7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2_7:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2-7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*","cpe:2.3:a:libopenjp2:libopenjp2_7:2.5.0-2ubuntu0.5:*:*:*:*:*:*:*"],"name":"libopenjp2-7","purl":"pkg:deb/ubuntu/libopenjp2-7@2.5.0-2ubuntu0.5?arch=amd64&distro=ubuntu-24.04&upstream=openjpeg2","type":"deb","version":"2.5.0-2ubuntu0.5","language":"","licenses":["BSD-2","BSD-3","LIBPNG","LIBTIFF","LIBTIFF-GLARSON","LIBTIFF-PIXAR","MIT","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libopenjp2-7/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libopenjp2-7/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libopenjp2-7:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openjpeg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2023-39328","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"openjpeg2","version":"2.5.0-2ubuntu0.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2023-39328","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39328","date":"2026-10-08","epss":0.00242,"percentile":0.14156}],"risk":0.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2023-39328"},"relatedVulnerabilities":[{"id":"CVE-2023-39328","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-39328","cwe":"CWE-400","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2023-39328","date":"2026-10-08","epss":0.00242,"percentile":0.14156}],"urls":["https://access.redhat.com/security/cve/CVE-2023-39328","https://bugzilla.redhat.com/show_bug.cgi?id=2219236","https://github.com/uclouvain/openjpeg/issues/1476","https://github.com/uclouvain/openjpeg/pull/1470","https://github.com/uclouvain/openjpeg/pull/1471"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-39328","description":"A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97687","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97687","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"risk":0.121,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97687"},"relatedVulnerabilities":[{"id":"CVE-2026-97687","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97687","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-97687","cwe":"CWE-440","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-97687","date":"2026-10-08","epss":0.00242,"percentile":0.14092}],"urls":["https://github.com/urllib3/urllib3/commit/07408cec79d1856d81bb42c74a904a24fdb9e465","https://github.com/urllib3/urllib3/commit/b6447295fff7b38fdffc67e0df9712d60cef3cc3","https://github.com/urllib3/urllib3/pull/5093","https://github.com/urllib3/urllib3/releases/tag/2.8.0","https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97687","description":"urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain separated because target-server TLS settings are incorrectly applied to the HTTPS proxy connection. The trigger is that an application uses an HTTPS proxy and configures target-server TLS settings that must remain separate from the proxy TLS handshake, including HTTPS forwarding with target-specific identity or credentials. Applying cert_reqs=CERT_NONE can overwrite proxy_ssl_context.verify_mode in place, and the mutation persists so later connections reusing the same context may connect to the HTTPS proxy without certificate verification. The attack mechanism is that an attacker intercepts and impersonates the HTTPS proxy after the effective proxy policy accepts the attacker's certificate. The impact is that the attacker can observe or modify forwarded traffic or receive a target TLS client certificate, while CONNECT tunneling still preserves the separate end-to-end target TLS connection. This issue is fixed in version 2.8.0."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105326","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105326","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105326","cwe":"CWE-88","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-105326","date":"2026-10-08","epss":0.00217,"percentile":0.11094}],"risk":0.1085,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105326"},"relatedVulnerabilities":[{"id":"CVE-2026-105326","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105326","cwe":"CWE-88","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-105326","date":"2026-10-08","epss":0.00217,"percentile":0.11094}],"urls":["https://access.redhat.com/errata/RHSA-2026:77638","https://access.redhat.com/security/cve/CVE-2026-105326","https://bugzilla.redhat.com/show_bug.cgi?id=2545835","https://github.com/OpenPrinting/cups/commit/1244ed9","https://github.com/OpenPrinting/cups/commit/611d1bd","https://github.com/OpenPrinting/cups/security/advisories/GHSA-r4wf-366f-f6g3"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105326","description":"An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subscription requests that supply a mailto notify-recipient-uri. The mailto notifier passes the recipient address to the configured sendmail program without ensuring it cannot be interpreted as command-line options. A remote attacker who can reach the CUPS service could supply a crafted recipient value starting with \"-\" to influence sendmail behavior. Successful exploitation depends on the installed mail transfer agent and CUPS network exposure, and may lead to execution of attacker-controlled commands with the privileges of the CUPS service user."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.1015,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66382"},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"0afbfa6e4f88ae06","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/ubuntu/libx11-6@2%3A1.8.7-1build1?arch=amd64&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"risk":0.0995,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-88806"},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"f0222bcd7168265e","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/ubuntu/libx11-data@2%3A1.8.7-1build1?arch=all&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"risk":0.0995,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-88806"},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-08","epss":0.00199,"percentile":0.08916}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"0afbfa6e4f88ae06","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/ubuntu/libx11-6@2%3A1.8.7-1build1?arch=amd64&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.0995,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-94283"},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"f0222bcd7168265e","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/ubuntu/libx11-data@2%3A1.8.7-1build1?arch=all&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"risk":0.0995,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-94283"},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-08","epss":0.00199,"percentile":0.08893}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3219","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3219","date":"2026-10-08","epss":0.0018,"percentile":0.06987}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3219"},"relatedVulnerabilities":[{"id":"CVE-2026-3219","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3219","date":"2026-10-08","epss":0.0018,"percentile":0.06987}],"urls":["https://github.com/pypa/pip/pull/13870","https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/","http://www.openwall.com/lists/oss-security/2026/04/20/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3219","description":"pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"f2f9ea64412a82e3","cpes":["cpe:2.3:a:libavahi-client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_client3:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_client3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-client3","purl":"pkg:deb/ubuntu/libavahi-client3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-client3/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-client3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-client3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-59529","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-59529"},"relatedVulnerabilities":[{"id":"CVE-2025-59529","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."}]},{"artifact":{"id":"e190b3f2d6ee823a","cpes":["cpe:2.3:a:libavahi-common-data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common-data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common_data:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common-data:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common_data:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common-data","purl":"pkg:deb/ubuntu/libavahi-common-data@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-common-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-common-data:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-59529","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-59529"},"relatedVulnerabilities":[{"id":"CVE-2025-59529","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."}]},{"artifact":{"id":"1439f27e2c1f750c","cpes":["cpe:2.3:a:libavahi-common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi-common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi_common3:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi-common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*","cpe:2.3:a:libavahi:libavahi_common3:0.8-13ubuntu6.2:*:*:*:*:*:*:*"],"name":"libavahi-common3","purl":"pkg:deb/ubuntu/libavahi-common3@0.8-13ubuntu6.2?arch=amd64&distro=ubuntu-24.04&upstream=avahi","type":"deb","version":"0.8-13ubuntu6.2","language":"","licenses":["sha256:66849d0ab7cbf0d770e40e00276ed8d264ed8974c0e064fb12814c0f80430c5d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libavahi-common3/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libavahi-common3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libavahi-common3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"avahi"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-59529","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"avahi","version":"0.8-13ubuntu6.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-59529","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"risk":0.0895,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-59529"},"relatedVulnerabilities":[{"id":"CVE-2025-59529","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-59529","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2025-59529","date":"2026-10-08","epss":0.00179,"percentile":0.06817}],"urls":["https://github.com/avahi/avahi/pull/808","https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q","https://zeropath.com/blog/avahi-simple-protocol-server-dos-cve-2025-59529","http://www.openwall.com/lists/oss-security/2025/12/19/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-59529","description":"Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ignores the documented client limit and accepts unlimited connections, allowing for easy local DoS. Although `CLIENTS_MAX` is defined, `server_work()` unconditionally `accept()`s and `client_new()` always appends the new client and increments `n_clients`. There is no check against the limit. When client cannot be accepted as a result of maximal socket number of avahi-daemon, it logs unconditionally error per each connection. Unprivileged local users can exhaust daemon memory and file descriptors, causing a denial of service system-wide for mDNS/DNS-SD. Exhausting local file descriptors causes increased system load caused by logging errors of each of request. Overloading prevents glibc calls using nss-mdns plugins to resolve `*.local.` names and link-local addresses. As of time of publication, no known patched versions are available, but a candidate fix is available in pull request 808, and some workarounds are available. Simple clients are offered for nss-mdns package functionality. It is not possible to disable the unix socket `/run/avahi-daemon/socket`, but resolution requests received via DBus are not affected directly. Tools avahi-resolve, avahi-resolve-address and avahi-resolve-host-name are not affected, they use DBus interface. It is possible to change permissions of unix socket after avahi-daemon is started. But avahi-daemon does not provide any configuration for it. Additional access restrictions like SELinux can also prevent unwanted tools to access the socket and keep resolution working for trusted users."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"b99f35328df2c1c9","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/ubuntu/gnupg-l10n@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5995b623e873af09","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/ubuntu/gpg-wks-client@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6357","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6357","date":"2026-10-08","epss":0.00171,"percentile":0.0587}],"risk":0.08549999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6357"},"relatedVulnerabilities":[{"id":"CVE-2026-6357","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6357","date":"2026-10-08","epss":0.00171,"percentile":0.0587}],"urls":["https://github.com/pypa/pip/pull/13923","https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes","http://www.openwall.com/lists/oss-security/2026/04/27/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357","description":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"de3f837e6f9ffb9c","cpes":["cpe:2.3:a:ghostscript:ghostscript:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"ghostscript","purl":"pkg:deb/ubuntu/ghostscript@10.02.1~dfsg1-0ubuntu7.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ghostscript/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/ghostscript/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ghostscript.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.list"},{"path":"/var/lib/dpkg/info/ghostscript.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.postinst"},{"path":"/var/lib/dpkg/info/ghostscript.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/ghostscript.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-101258"},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"534916fabd9863d8","cpes":["cpe:2.3:a:libgs-common:libgs-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs-common:libgs_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs_common:libgs_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs:libgs_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"libgs-common","purl":"pkg:deb/ubuntu/libgs-common@10.02.1~dfsg1-0ubuntu7.9?arch=all&distro=ubuntu-24.04&upstream=ghostscript","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs-common/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libgs-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs-common.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-101258"},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"0db51484e969d817","cpes":["cpe:2.3:a:libgs10:libgs10:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"libgs10","purl":"pkg:deb/ubuntu/libgs10@10.02.1~dfsg1-0ubuntu7.9?arch=amd64&distro=ubuntu-24.04&upstream=ghostscript","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libgs10/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs10:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-101258"},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"4588322eaa33fbd9","cpes":["cpe:2.3:a:libgs10-common:libgs10-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10-common:libgs10_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10_common:libgs10_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10-common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*","cpe:2.3:a:libgs10:libgs10_common:10.02.1\\~dfsg1-0ubuntu7.9:*:*:*:*:*:*:*"],"name":"libgs10-common","purl":"pkg:deb/ubuntu/libgs10-common@10.02.1~dfsg1-0ubuntu7.9?arch=all&distro=ubuntu-24.04&upstream=ghostscript","type":"deb","version":"10.02.1~dfsg1-0ubuntu7.9","language":"","licenses":["AGPL-3","AGPL-3+","Apache-2.0","BSD-3-Clause","BSD-3-Clause~Adobe","Expat","Expat~Ghostgum","Expat~SunSoft","FTL","GAP~configure","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL-2.1","MIT-Open-Group","NTP~Lucent","NTP~WSU","X11","ZLIB","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgs10-common/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libgs10-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs10-common.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgs10-common.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libgs10-common.list"}],"upstreams":[{"name":"ghostscript"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-101258","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"ghostscript","version":"10.02.1~dfsg1-0ubuntu7.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-101258","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-101258"},"relatedVulnerabilities":[{"id":"CVE-2026-101258","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101258","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-101258","date":"2026-10-08","epss":0.00151,"percentile":0.0373}],"urls":["https://access.redhat.com/security/cve/CVE-2026-101258","https://bugzilla.redhat.com/show_bug.cgi?id=2542396","https://github.com/v12-security/pocs/tree/main/ghostscript"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101258","description":"A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"ae36307ca07e59fc","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.1\\+git230720-4ubuntu2.5:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/ubuntu/libtiff6@4.5.1%2Bgit230720-4ubuntu2.5?arch=amd64&distro=ubuntu-24.04&upstream=tiff","type":"deb","version":"4.5.1+git230720-4ubuntu2.5","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18495","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tiff","version":"4.5.1+git230720-4ubuntu2.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18495","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18495","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18495","date":"2026-10-08","epss":0.00117,"percentile":0.01527}],"risk":0.0585,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18495"},"relatedVulnerabilities":[{"id":"CVE-2026-18495","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","metrics":{"baseScore":6.1,"impactScore":4.8,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18495","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18495","date":"2026-10-08","epss":0.00117,"percentile":0.01527}],"urls":["https://access.redhat.com/errata/RHSA-2026:53467","https://access.redhat.com/security/cve/CVE-2026-18495","https://bugzilla.redhat.com/show_bug.cgi?id=2531414","https://gitlab.com/libtiff/libtiff/-/merge_requests/729","https://gitlab.com/libtiff/libtiff/-/tree/67fd283d276f09db54dc39b9ef7b979d4b45c4b1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18495","description":"A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption."}]},{"artifact":{"id":"0afbfa6e4f88ae06","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/ubuntu/libx11-6@2%3A1.8.7-1build1?arch=amd64&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94285","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-94285","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-94285"},"relatedVulnerabilities":[{"id":"CVE-2026-94285","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94285","description":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"f0222bcd7168265e","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/ubuntu/libx11-data@2%3A1.8.7-1build1?arch=all&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94285","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-94285","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-94285"},"relatedVulnerabilities":[{"id":"CVE-2026-94285","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":5.1,"impactScore":2.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94285","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94285","date":"2026-10-08","epss":0.00111,"percentile":0.01263}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=980868483446f24f9658d26aa5bfa42f3da6dd3a"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94285","description":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"04f1ff7ee24f6dbf","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:24.0\\+dfsg-1ubuntu1.3:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/ubuntu/python3-pip-whl@24.0%2Bdfsg-1ubuntu1.3?arch=all&distro=ubuntu-24.04&upstream=python-pip","type":"deb","version":"24.0+dfsg-1ubuntu1.3","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","LGPL-2.1","LGPL-2.1+","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-25645","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python-pip","version":"24.0+dfsg-1ubuntu1.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-25645","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-25645","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25645","date":"2026-10-08","epss":0.00185,"percentile":0.07433}],"risk":0.05550000000000001,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-25645"},"relatedVulnerabilities":[{"id":"CVE-2026-25645","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25645","cwe":"CWE-377","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-25645","date":"2026-10-08","epss":0.00185,"percentile":0.07433}],"urls":["https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7","https://github.com/psf/requests/releases/tag/v2.33.0","https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25645","description":"Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system temporary directory. If the target file already exists, it is reused without validation. A local attacker with write access to the temp directory could pre-create a malicious file that would be loaded in place of the legitimate one. Standard usage of the Requests library is not affected by this vulnerability. Only applications that call `extract_zipped_paths()` directly are impacted. Starting in version 2.33.0, the library extracts files to a non-deterministic location. If developers are unable to upgrade, they can set `TMPDIR` in their environment to a directory with restricted write access."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"b92fea664c3f8f85","cpes":["cpe:2.3:a:python3.12-venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_venv:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_venv:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-venv","purl":"pkg:deb/ubuntu/python3.12-venv@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/python3.12-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-venv.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.list"},{"path":"/var/lib/dpkg/info/python3.12-venv.postinst","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.12-venv.postrm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.12-venv.prerm","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/python3.12-venv.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"0afbfa6e4f88ae06","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/ubuntu/libx11-6@2%3A1.8.7-1build1?arch=amd64&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-94284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"risk":0.051500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-94284"},"relatedVulnerabilities":[{"id":"CVE-2026-94284","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94284","description":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"f0222bcd7168265e","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.7-1build1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.7-1build1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/ubuntu/libx11-data@2%3A1.8.7-1build1?arch=all&distro=ubuntu-24.04&upstream=libx11","type":"deb","version":"2:1.8.7-1build1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94284","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libx11","version":"2:1.8.7-1build1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-94284","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"risk":0.051500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-94284"},"relatedVulnerabilities":[{"id":"CVE-2026-94284","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94284","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94284","date":"2026-10-08","epss":0.00103,"percentile":0.00924}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=1b7904002d212eed40949ccf4e8e7156f9fec0e2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94284","description":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"17317631a09f6a3f","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"c37cad8d5a3a6548","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"817535dcd7b4fdf9","cpes":["cpe:2.3:a:systemd-standalone-sysusers:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone-sysusers:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone_sysusers:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone_sysusers:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"systemd-standalone-sysusers","purl":"pkg:deb/ubuntu/systemd-standalone-sysusers@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-standalone-sysusers/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/systemd-standalone-sysusers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-standalone-sysusers.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/systemd-standalone-sysusers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-standalone-sysusers.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/systemd-standalone-sysusers.list"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"b99f35328df2c1c9","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/ubuntu/gnupg-l10n@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5995b623e873af09","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/ubuntu/gpg-wks-client@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-9403","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"risk":0.0108,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-9403"},"relatedVulnerabilities":[{"id":"CVE-2025-9403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-9403","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"risk":0.0108,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-9403"},"relatedVulnerabilities":[{"id":"CVE-2025-9403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well."}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-55453","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-55453","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-55453"},"relatedVulnerabilities":[{"id":"CVE-2026-55453","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-55480","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-55480","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-55480"},"relatedVulnerabilities":[{"id":"CVE-2026-55480","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"446bdf2f3d1206f1","cpes":["cpe:2.3:a:libcups2t64:libcups2t64:2.4.7-1.2ubuntu7.14:*:*:*:*:*:*:*"],"name":"libcups2t64","purl":"pkg:deb/ubuntu/libcups2t64@2.4.7-1.2ubuntu7.14?arch=amd64&distro=ubuntu-24.04&upstream=cups","type":"deb","version":"2.4.7-1.2ubuntu7.14","language":"","licenses":["Apache-2.0","Apache-2.0-with-GPL2-LGPL2-Exception","BSD-2-Clause","FSFUL","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcups2t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libcups2t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libcups2t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"cups"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-61702","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"cups","version":"2.4.7-1.2ubuntu7.14"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-61702","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-61702"},"relatedVulnerabilities":[{"id":"CVE-2026-61702","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"d6f9a7fd2bf3dd0b","cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.43-5ubuntu0.7:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.43-5ubuntu0.7:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.43-5ubuntu0.7:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.43-5ubuntu0.7:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.43-5ubuntu0.7:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.43-5ubuntu0.7:*:*:*:*:*:*:*"],"name":"libpng16-16t64","purl":"pkg:deb/ubuntu/libpng16-16t64@1.6.43-5ubuntu0.7?arch=amd64&distro=ubuntu-24.04&upstream=libpng1.6","type":"deb","version":"1.6.43-5ubuntu0.7","language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16t64/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libpng16-16t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libpng1.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46675","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libpng1.6","version":"1.6.43-5ubuntu0.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46675","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46675"},"relatedVulnerabilities":[{"id":"CVE-2026-46675","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"ae36307ca07e59fc","cpes":["cpe:2.3:a:libtiff6:libtiff6:4.5.1\\+git230720-4ubuntu2.5:*:*:*:*:*:*:*"],"name":"libtiff6","purl":"pkg:deb/ubuntu/libtiff6@4.5.1%2Bgit230720-4ubuntu2.5?arch=amd64&distro=ubuntu-24.04&upstream=tiff","type":"deb","version":"4.5.1+git230720-4ubuntu2.5","language":"","licenses":["Hylafax"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtiff6/copyright","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/usr/share/doc/libtiff6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","layerID":"sha256:860770f205a57d020f248ecfe83a522b9647276062e1c84ce2a3867b9947ae6d","accessPath":"/var/lib/dpkg/info/libtiff6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"tiff"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-36849","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tiff","version":"4.5.1+git230720-4ubuntu2.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-36849","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-36849"},"relatedVulnerabilities":[{"id":"CVE-2026-36849","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]}],"grade":"A","score":"100.00","as_of":"2026-10-10T02:36:33.651Z","grype_db_version":"2026-10-09T06:32:32.000Z"}