{"grype_matches":[{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.2"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42055","versionConstraint":">= 1.30.0, < 1.30.3||>= 1.31.0, < 1.31.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.2"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42055","versionConstraint":">= 1.30.0, < 1.30.3||>= 1.31.0, < 1.31.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42055","fix":{"state":"fixed","versions":["1.30.3","1.31.2"],"available":[{"date":"2026-06-18","kind":"first-observed","version":"1.30.3"},{"date":"2026-06-18","kind":"first-observed","version":"1.31.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42055","cwe":"CWE-122","type":"Secondary","source":"f5sirt@f5.com"},{"cve":"CVE-2026-42055","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42055","cwe":"CWE-131","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42055","date":"2026-10-07","epss":0.06537,"percentile":0.93623}],"risk":5.218705,"urls":["https://my.f5.com/manage/s/article/K000161584","https://access.redhat.com/errata/RHSA-2026:27197","https://access.redhat.com/errata/RHSA-2026:36331","https://access.redhat.com/errata/RHSA-2026:36364","https://access.redhat.com/errata/RHSA-2026:36618","https://access.redhat.com/errata/RHSA-2026:36639","https://access.redhat.com/errata/RHSA-2026:38847","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-42055","https://bugzilla.redhat.com/show_bug.cgi?id=2489866","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42055.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42055","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"809ea4b423ef5f0e","cpes":["cpe:2.3:a:libgnutls30t64:libgnutls30t64:3.8.9-3\\+deb13u4:*:*:*:*:*:*:*"],"name":"libgnutls30t64","purl":"pkg:deb/debian/libgnutls30t64@3.8.9-3%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=gnutls28","type":"deb","version":"3.8.9-3+deb13u4","language":"","licenses":["sha256:a07e99815cf1998f1dabbc21fe199460bfa09b85ead0d56b49a32cac3d1791b5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgnutls30t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libgnutls30t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libgnutls30t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gnutls28"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2011-3389","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnutls28","version":"3.8.9-3+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2011-3389","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-07","epss":0.73327,"percentile":0.99453}],"risk":3.66635,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."},"relatedVulnerabilities":[{"id":"CVE-2011-3389","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2011-3389","cwe":"CWE-326","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2011-3389","date":"2026-10-07","epss":0.73327,"percentile":0.99453}],"urls":["http://blog.mozilla.com/security/2011/09/27/attack-against-tls-protected-communications/","http://blogs.technet.com/b/msrc/archive/2011/09/26/microsoft-releases-security-advisory-2588513.aspx","http://blogs.technet.com/b/srd/archive/2011/09/26/is-ssl-broken-more-about-security-advisory-2588513.aspx","http://curl.haxx.se/docs/adv_20120124B.html","http://downloads.asterisk.org/pub/security/AST-2016-001.html","http://ekoparty.org/2011/juliano-rizzo.php","http://eprint.iacr.org/2004/111","http://eprint.iacr.org/2006/136","http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html","http://isc.sans.edu/diary/SSL+TLS+part+3+/11635","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00001.html","http://lists.apple.com/archives/Security-announce/2011//Oct/msg00002.html","http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html","http://lists.apple.com/archives/security-announce/2012/Jul/msg00001.html","http://lists.apple.com/archives/security-announce/2012/May/msg00001.html","http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html","http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00049.html","http://lists.opensuse.org/opensuse-security-announce/2012-01/msg00051.html","http://lists.opensuse.org/opensuse-security-announce/2012-05/msg00009.html","http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html","http://marc.info/?l=bugtraq&m=132750579901589&w=2","http://marc.info/?l=bugtraq&m=132872385320240&w=2","http://marc.info/?l=bugtraq&m=133365109612558&w=2","http://marc.info/?l=bugtraq&m=133728004526190&w=2","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://marc.info/?l=bugtraq&m=134254957702612&w=2","http://my.opera.com/securitygroup/blog/2011/09/28/the-beast-ssl-tls-issue","http://osvdb.org/74829","http://rhn.redhat.com/errata/RHSA-2012-0508.html","http://rhn.redhat.com/errata/RHSA-2013-1455.html","http://secunia.com/advisories/45791","http://secunia.com/advisories/47998","http://secunia.com/advisories/48256","http://secunia.com/advisories/48692","http://secunia.com/advisories/48915","http://secunia.com/advisories/48948","http://secunia.com/advisories/49198","http://secunia.com/advisories/55322","http://secunia.com/advisories/55350","http://secunia.com/advisories/55351","http://security.gentoo.org/glsa/glsa-201203-02.xml","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://support.apple.com/kb/HT4999","http://support.apple.com/kb/HT5001","http://support.apple.com/kb/HT5130","http://support.apple.com/kb/HT5281","http://support.apple.com/kb/HT5501","http://support.apple.com/kb/HT6150","http://technet.microsoft.com/security/advisory/2588513","http://vnhacker.blogspot.com/2011/09/beast.html","http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","http://www.debian.org/security/2012/dsa-2398","http://www.educatedguesswork.org/2011/09/security_impact_of_the_rizzodu.html","http://www.ibm.com/developerworks/java/jdk/alerts/","http://www.imperialviolet.org/2011/09/23/chromeandbeast.html","http://www.insecure.cl/Beast-SSL.rar","http://www.kb.cert.org/vuls/id/864643","http://www.mandriva.com/security/advisories?name=MDVSA-2012:058","http://www.opera.com/docs/changelogs/mac/1151/","http://www.opera.com/docs/changelogs/mac/1160/","http://www.opera.com/docs/changelogs/unix/1151/","http://www.opera.com/docs/changelogs/unix/1160/","http://www.opera.com/docs/changelogs/windows/1151/","http://www.opera.com/docs/changelogs/windows/1160/","http://www.opera.com/support/kb/view/1004/","http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html","http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html","http://www.redhat.com/support/errata/RHSA-2011-1384.html","http://www.redhat.com/support/errata/RHSA-2012-0006.html","http://www.securityfocus.com/bid/49388","http://www.securityfocus.com/bid/49778","http://www.securitytracker.com/id/1029190","http://www.securitytracker.com/id?1025997","http://www.securitytracker.com/id?1026103","http://www.securitytracker.com/id?1026704","http://www.ubuntu.com/usn/USN-1263-1","http://www.us-cert.gov/cas/techalerts/TA12-010A.html","https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_fetchmail","https://bugzilla.novell.com/show_bug.cgi?id=719047","https://bugzilla.redhat.com/show_bug.cgi?id=737506","https://cert-portal.siemens.com/productcert/pdf/ssa-556833.pdf","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-006","https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862","https://hermes.opensuse.org/messages/13154861","https://hermes.opensuse.org/messages/13155432","https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14752"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2011-3389","description":"The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-6110","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-6110","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-07","epss":0.20906,"percentile":0.97505}],"risk":1.0453000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."},"relatedVulnerabilities":[{"id":"CVE-2019-6110","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2019-6110","cwe":"CWE-838","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2019-6110","date":"2026-10-07","epss":0.20906,"percentile":0.97505}],"urls":["https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf","https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.c","https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c","https://security.gentoo.org/glsa/201903-16","https://security.netapp.com/advisory/ntap-20190213-0001/","https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt","https://www.exploit-db.com/exploits/46193/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-6110","description":"In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"risk":1.01325,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-07","epss":0.01351,"percentile":0.70652}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-0456","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-0456","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-07","epss":0.19036,"percentile":0.97243}],"risk":0.9518000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."},"relatedVulnerabilities":[{"id":"CVE-2008-0456","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-0456","cwe":"CWE-74","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-0456","date":"2026-10-07","epss":0.19036,"percentile":0.97243}],"urls":["http://lists.apple.com/archives/security-announce/2009/May/msg00002.html","http://rhn.redhat.com/errata/RHSA-2013-0130.html","http://secunia.com/advisories/29348","http://secunia.com/advisories/35074","http://security.gentoo.org/glsa/glsa-200803-19.xml","http://securityreason.com/securityalert/3575","http://securitytracker.com/id?1019256","http://support.apple.com/kb/HT3549","http://www.mindedsecurity.com/MSA01150108.html","http://www.securityfocus.com/archive/1/486847/100/0/threaded","http://www.securityfocus.com/bid/27409","http://www.us-cert.gov/cas/techalerts/TA09-133A.html","http://www.vupen.com/english/advisories/2009/1297","https://exchange.xforce.ibmcloud.com/vulnerabilities/39893","https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E","https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-0456","description":"CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) \"406 Not Acceptable\" or (2) \"300 Multiple Choices\" HTTP response when the extension is omitted in a request for the file."}]},{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.2"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42530","versionConstraint":">= 1.31.0, < 1.31.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.2"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42530","versionConstraint":">= 1.31.0, < 1.31.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42530","fix":{"state":"fixed","versions":["1.31.2"],"available":[{"date":"2026-06-18","kind":"first-observed","version":"1.31.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42530","cwe":"CWE-416","type":"Secondary","source":"f5sirt@f5.com"},{"cve":"CVE-2026-42530","cwe":"CWE-416","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42530","date":"2026-10-07","epss":0.01145,"percentile":0.65741}],"risk":0.9140916666666667,"urls":["https://my.f5.com/manage/s/article/K000161616","https://access.redhat.com/errata/RHSA-2026:20351","https://access.redhat.com/security/cve/CVE-2026-42530","https://bugzilla.redhat.com/show_bug.cgi?id=2489872","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42530.json"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42530","description":"NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42533","versionConstraint":">= 0.9.6, < 1.30.4||>= 1.31.0, < 1.31.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-42533","versionConstraint":">= 0.9.6, < 1.30.4||>= 1.31.0, < 1.31.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-42533","fix":{"state":"fixed","versions":["1.30.4","1.31.3"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"1.30.4"},{"date":"2026-07-21","kind":"first-observed","version":"1.31.3"}]},"cvss":[{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42533","cwe":"CWE-122","type":"Secondary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-42533","date":"2026-10-07","epss":0.00894,"percentile":0.58246}],"risk":0.7889550000000001,"urls":["https://my.f5.com/manage/s/article/K000162097"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42533","description":"A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\n Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19931","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"risk":0.70218,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection."},"relatedVulnerabilities":[{"id":"CVE-2026-19931","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-07","epss":0.00747,"percentile":0.5342}],"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63292","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63292","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-07","epss":0.00876,"percentile":0.57718}],"risk":0.657,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63292","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63292","cwe":"CWE-121","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63292","date":"2026-10-07","epss":0.00876,"percentile":0.57718}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63292","description":"Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15778","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-15778","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-07","epss":0.12996,"percentile":0.96236}],"risk":0.6498,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""},"relatedVulnerabilities":[{"id":"CVE-2020-15778","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.6},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-15778","cwe":"CWE-78","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-15778","date":"2026-10-07","epss":0.12996,"percentile":0.96236}],"urls":["https://access.redhat.com/errata/RHSA-2024:3166","https://github.com/cpandya2909/CVE-2020-15778/","https://news.ycombinator.com/item?id=25005567","https://security.gentoo.org/glsa/202212-06","https://security.netapp.com/advisory/ntap-20200731-0007/","https://www.openssh.com/security.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15778","description":"scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of \"anomalous argument transfers\" because that could \"stand a great chance of breaking existing workflows.\""}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11856","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"risk":0.6467200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`."},"relatedVulnerabilities":[{"id":"CVE-2026-11856","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-07","epss":0.00688,"percentile":0.51199}],"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-66046","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-66046","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-07","epss":0.00742,"percentile":0.53242}],"risk":0.60102,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."},"relatedVulnerabilities":[{"id":"CVE-2026-66046","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-66046","cwe":"CWE-407","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-66046","date":"2026-10-07","epss":0.00742,"percentile":0.53242}],"urls":["https://github.com/libexpat/libexpat/pull/1321","https://www.vulncheck.com/advisories/expat-denial-of-service-via-storeatts-quadratic-complexity"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-66046","description":"Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"risk":0.5982050000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set \"super cookies\" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains."},"relatedVulnerabilities":[{"id":"CVE-2026-8924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-07","epss":0.00661,"percentile":0.5004}],"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57941","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-57941","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-07","epss":0.006,"percentile":0.47055}],"risk":0.5640000000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-57941","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57941","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-57941","date":"2026-10-07","epss":0.006,"percentile":0.47055}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57941","description":"Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-10536","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"risk":0.5621200000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation."},"relatedVulnerabilities":[{"id":"CVE-2026-10536","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-07","epss":0.00598,"percentile":0.46935}],"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."}]},{"artifact":{"id":"642df124d4347f65","cpes":["cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.11:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.11","type":"npm","version":"7.5.11","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-23hp-3jrh-7fpw","versionConstraint":"<=7.5.18 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.11"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-23hp-3jrh-7fpw","fix":{"state":"fixed","versions":["7.5.19"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.5.19"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59873","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59873","date":"2026-10-07","epss":0.00644,"percentile":0.49245}],"risk":0.55867,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw","https://nvd.nist.gov/vuln/detail/CVE-2026-59873","https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3","https://github.com/isaacs/node-tar/releases/tag/v7.5.19"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-23hp-3jrh-7fpw","description":"node-tar: Decompression/parse DoS via unlimited input"},"relatedVulnerabilities":[{"id":"CVE-2026-59873","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59873","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59873","date":"2026-10-07","epss":0.00644,"percentile":0.49245}],"urls":["https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3","https://github.com/isaacs/node-tar/releases/tag/v7.5.19","https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59873","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9079","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"risk":0.54896,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[{"id":"CVE-2026-9079","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-07","epss":0.00584,"percentile":0.46181}],"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18924","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"risk":0.52852,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process."},"relatedVulnerabilities":[{"id":"CVE-2026-18924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-07","epss":0.00584,"percentile":0.46203}],"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56154","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56154","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-07","epss":0.00562,"percentile":0.44993}],"risk":0.5282800000000001,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56154","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56154","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56154","date":"2026-10-07","epss":0.00562,"percentile":0.44993}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56154","description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-0086","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-0086","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-07","epss":0.10168,"percentile":0.9555}],"risk":0.5084000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"},"relatedVulnerabilities":[{"id":"CVE-2007-0086","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","metrics":{"baseScore":7.8,"impactScore":6.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-0086","cwe":"CWE-400","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-0086","date":"2026-10-07","epss":0.10168,"percentile":0.9555}],"urls":["http://osvdb.org/33456","http://www.securityfocus.com/archive/1/455833/100/0/threaded","http://www.securityfocus.com/archive/1/455879/100/0/threaded","http://www.securityfocus.com/archive/1/455882/100/0/threaded","http://www.securityfocus.com/archive/1/455920/100/0/threaded"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-0086","description":"The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment.  NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal"}]},{"artifact":{"id":"b958288bb0c2bb20","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.1.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.1.0","type":"npm","version":"10.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.3.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mwp4-54f8-5fhr","versionConstraint":"<=10.3.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mwp4-54f8-5fhr","fix":{"state":"fixed","versions":["10.3.1"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"10.3.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69192","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69192","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69192","date":"2026-10-07","epss":0.00663,"percentile":0.50116}],"risk":0.50388,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr","https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mwp4-54f8-5fhr","description":"ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-69192","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69192","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69192","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69192","date":"2026-10-07","epss":0.00663,"percentile":0.50116}],"urls":["https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e","https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69192","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1."}]},{"artifact":{"id":"642df124d4347f65","cpes":["cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.11:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.11","type":"npm","version":"7.5.11","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-8x88-c5mf-7j5w","versionConstraint":"<=7.5.17 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.11"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-8x88-c5mf-7j5w","fix":{"state":"fixed","versions":["7.5.18"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.5.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59874","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59874","date":"2026-10-07","epss":0.00644,"percentile":0.49246}],"risk":0.50232,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w","https://nvd.nist.gov/vuln/detail/CVE-2026-59874","https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5","https://github.com/isaacs/node-tar/releases/tag/v7.5.18"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-8x88-c5mf-7j5w","description":"node-tar: Negative tar entry size causes infinite loop in archive replace"},"relatedVulnerabilities":[{"id":"CVE-2026-59874","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59874","cwe":"CWE-835","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59874","date":"2026-10-07","epss":0.00644,"percentile":0.49246}],"urls":["https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5","https://github.com/isaacs/node-tar/releases/tag/v7.5.18","https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59874","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18."}]},{"artifact":{"id":"fad8c9725b44729b","cpes":["cpe:2.3:a:python3-setuptools-whl:python3-setuptools-whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools-whl:python3_setuptools_whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_whl:python3-setuptools-whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools_whl:python3_setuptools_whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3-setuptools-whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3-setuptools:python3_setuptools_whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3-setuptools-whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3_setuptools:python3_setuptools_whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-setuptools-whl:78.1.1-0.1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_setuptools_whl:78.1.1-0.1:*:*:*:*:*:*:*"],"name":"python3-setuptools-whl","purl":"pkg:deb/debian/python3-setuptools-whl@78.1.1-0.1?arch=all&distro=debian-13.7&upstream=setuptools","type":"deb","version":"78.1.1-0.1","language":"","licenses":["Apache-2.0","BSD-3-Clause","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-setuptools-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-setuptools-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-setuptools-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-setuptools-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-setuptools-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-setuptools-whl.list"}],"upstreams":[{"name":"setuptools"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-23949","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"setuptools","version":"78.1.1-0.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-23949","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23949","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23949","date":"2026-10-07","epss":0.00618,"percentile":0.4796}],"risk":0.49748999999999993,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-23949","description":"jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the intended extraction directory when malicious tar archives are processed. The strip_first_component filter splits the path on the first `/` and extracts the second component, while allowing `../` sequences. Paths like `dummy_dir/../../etc/passwd` become `../../etc/passwd`. Note that this suffers from a nested tarball attack as well with multi-level tar files such as `dummy_dir/inner.tar.gz`, where the inner.tar.gz includes a traversal `dummy_dir/../../config/.env` that also gets translated to `../../config/.env`. Version 6.1.0 contains a patch for the issue."},"relatedVulnerabilities":[{"id":"CVE-2026-23949","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","metrics":{"baseScore":8.6,"impactScore":4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23949","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-23949","date":"2026-10-07","epss":0.00618,"percentile":0.4796}],"urls":["https://github.com/jaraco/jaraco.context/blob/main/jaraco/context/__init__.py#L74-L91","https://github.com/jaraco/jaraco.context/commit/7b26a42b525735e4085d2e994e13802ea339d5f9","https://github.com/jaraco/jaraco.context/security/advisories/GHSA-58pv-8j8x-9vj2","https://github.com/pypa/setuptools/blob/main/setuptools/_vendor/jaraco/context.py#L55-L76"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23949","description":"jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0. The vulnerability may allow attackers to extract files outside the intended extraction directory when malicious tar archives are processed. The strip_first_component filter splits the path on the first `/` and extracts the second component, while allowing `../` sequences. Paths like `dummy_dir/../../etc/passwd` become `../../etc/passwd`. Note that this suffers from a nested tarball attack as well with multi-level tar files such as `dummy_dir/inner.tar.gz`, where the inner.tar.gz includes a traversal `dummy_dir/../../config/.env` that also gets translated to `../../config/.env`. Version 6.1.0 contains a patch for the issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59797","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59797","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-07","epss":0.0052,"percentile":0.42337}],"risk":0.4888,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-59797","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59797","cwe":"CWE-269","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-59797","date":"2026-10-07","epss":0.0052,"percentile":0.42337}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/22"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59797","description":"Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rgw5-rvv9-x895","versionConstraint":">=2.0.0,<2.1.4 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rgw5-rvv9-x895","fix":{"state":"fixed","versions":["2.1.4"],"available":[{"date":"2026-08-03","kind":"first-observed","version":"2.1.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69152","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69152","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69152","date":"2026-10-07","epss":0.00647,"percentile":0.49372}],"risk":0.48525,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895","https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://nvd.nist.gov/vuln/detail/CVE-2026-69152"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rgw5-rvv9-x895","description":"brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation"},"relatedVulnerabilities":[{"id":"CVE-2026-69152","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69152","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69152","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69152","date":"2026-10-07","epss":0.00647,"percentile":0.49372}],"urls":["https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac","https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69152","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop. The fix for CVE-2026-14257 is bypassed by the vulnerability. This issue is fixed in versions 1.1.18, 2.1.4, 3.0.6, and 5.0.9."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-mh99-v99m-4gvg","versionConstraint":">=2.0.0,<2.1.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-mh99-v99m-4gvg","fix":{"state":"fixed","versions":["2.1.3"],"available":[{"date":"2026-08-01","kind":"first-observed","version":"2.1.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14257","cwe":"CWE-400","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"},{"cve":"CVE-2026-14257","cwe":"CWE-770","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"}],"epss":[{"cve":"CVE-2026-14257","date":"2026-10-07","epss":0.00643,"percentile":0.49186}],"risk":0.48225000000000007,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-mh99-v99m-4gvg","https://nvd.nist.gov/vuln/detail/CVE-2026-14257","https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5","https://github.com/juliangruber/brace-expansion","https://www.npmjs.com/package/brace-expansion","https://github.com/juliangruber/brace-expansion/pull/129","https://github.com/juliangruber/brace-expansion/pull/130","https://github.com/juliangruber/brace-expansion/pull/136","https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d","https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031","https://github.com/juliangruber/brace-expansion/commit/d13ff455a58b0d56704f0111e3c2a0b16ceb06eb"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-mh99-v99m-4gvg","description":"brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash"},"relatedVulnerabilities":[{"id":"CVE-2026-14257","cvss":[{"type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-14257","cwe":"CWE-400","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"},{"cve":"CVE-2026-14257","cwe":"CWE-770","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"}],"epss":[{"cve":"CVE-2026-14257","date":"2026-10-07","epss":0.00643,"percentile":0.49186}],"urls":["https://github.com/juliangruber/brace-expansion","https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5","https://www.npmjs.com/package/brace-expansion"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-14257","description":"brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count and string length until the process hits a fatal, uncatchable out-of-memory error. About 7.5 KB of input ('{a,b}'.repeat(1500)) crashes a default Node.js process. Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch / glob brace patterns - can be crashed by a small request. Fixed in 5.0.8 by adding a maxLength option (default 4,000,000) that bounds accumulated output and intermediate arrays."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15308","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15308","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"risk":0.47774999999999995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data."},"relatedVulnerabilities":[{"id":"CVE-2026-15308","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15308","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15308","date":"2026-10-07","epss":0.00637,"percentile":0.48884}],"urls":["https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9","https://github.com/python/cpython/commit/1e7956f1a722df9aabc509c30f8fbdc3a2b4fdc7","https://github.com/python/cpython/commit/785df8f743800661961528970f8598edcd291c14","https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced","https://github.com/python/cpython/commit/bcf98ddbc40ec9b3ee87da0124a5660b19b7e606","https://github.com/python/cpython/commit/c2390b9376e35a701ed3acc597b8fc87546c9b00","https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd","https://github.com/python/cpython/issues/153030","https://github.com/python/cpython/pull/153031","https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/","http://www.openwall.com/lists/oss-security/2026/07/09/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15308","description":"The incremental HTML parser (html.parser.HTMLParser) allows for CPU\ndenial-of-service through repeated unterminated markup declarations when\nprocessing uncontrolled data."}]},{"artifact":{"id":"e9d28bf4fecb65b4","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"8d18bdf2d28de8c0","cpes":["cpe:2.3:a:perl:perl:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"ec18de78d97e6b78","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"risk":0.47250000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.  Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.  Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-07","epss":0.0063,"percentile":0.48531}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-07","epss":0.00592,"percentile":0.46608}],"risk":0.46768,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-07","epss":0.00592,"percentile":0.46608}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60000","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-60000","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-07","epss":0.00618,"percentile":0.47972}],"risk":0.4635,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."},"relatedVulnerabilities":[{"id":"CVE-2026-60000","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60000","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60000","date":"2026-10-07","epss":0.00618,"percentile":0.47972}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60000","description":"sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56449","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56449","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-07","epss":0.00612,"percentile":0.47655}],"risk":0.45899999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56449","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56449","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56449","date":"2026-10-07","epss":0.00612,"percentile":0.47655}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/18"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56449","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-48005","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48005","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-07","epss":0.00606,"percentile":0.47327}],"risk":0.4545,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-48005","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48005","cwe":"CWE-306","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-48005","date":"2026-10-07","epss":0.00606,"percentile":0.47327}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/15"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48005","description":"Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8927","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"risk":0.4525,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`."},"relatedVulnerabilities":[{"id":"CVE-2026-8927","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-07","epss":0.005,"percentile":0.40914}],"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-2768","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-07","epss":0.08615,"percentile":0.94968}],"risk":0.4307500000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."},"relatedVulnerabilities":[{"id":"CVE-2007-2768","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2768","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2768","date":"2026-10-07","epss":0.08615,"percentile":0.94968}],"urls":["http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0635.html","http://www.osvdb.org/34601","https://security.netapp.com/advisory/ntap-20191107-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2768","description":"OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243."}]},{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-60005","versionConstraint":">= 1.15.8, < 1.30.4||>= 1.31.0, < 1.31.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-60005","versionConstraint":">= 1.15.8, < 1.30.4||>= 1.31.0, < 1.31.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-60005","fix":{"state":"fixed","versions":["1.30.4","1.31.3"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"1.30.4"},{"date":"2026-07-21","kind":"first-observed","version":"1.31.3"}]},"cvss":[{"type":"Primary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60005","cwe":"CWE-908","type":"Primary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-60005","date":"2026-10-07","epss":0.00531,"percentile":0.43102}],"risk":0.4248,"urls":["https://my.f5.com/manage/s/article/K000162100"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60005","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80229","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"risk":0.42224999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[{"id":"CVE-2026-80229","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-07","epss":0.00563,"percentile":0.45026}],"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.7","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6951","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6951","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-07","epss":0.08359,"percentile":0.94829}],"risk":0.41795,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."},"relatedVulnerabilities":[{"id":"CVE-2018-6951","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6951","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6951","date":"2026-10-07","epss":0.08359,"percentile":0.94829}],"urls":["http://www.securityfocus.com/bid/103044","https://git.savannah.gnu.org/cgit/patch.git/commit/?id=f290f48a621867084884bfff87f8093c15195e6a","https://savannah.gnu.org/bugs/index.php?53132","https://security.gentoo.org/glsa/201904-17","https://usn.ubuntu.com/3624-1/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6951","description":"An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a \"mangled rename\" issue."}]},{"artifact":{"id":"c87764051de550d7","cpes":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:4.2.0:*:*:*:*:node.js:*:*"],"name":"http-cache-semantics","purl":"pkg:npm/http-cache-semantics@4.2.0","type":"npm","version":"4.2.0","language":"javascript","licenses":["BSD-2-Clause"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/http-cache-semantics/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-ch52-4w7c-c8xp","versionConstraint":"<=4.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"http-cache-semantics","version":"4.2.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-ch52-4w7c-c8xp","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-07","epss":0.00531,"percentile":0.43085}],"risk":0.41418,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-93748","https://github.com/kornelski/http-cache-semantics/issues/56","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-ch52-4w7c-c8xp","description":"http-cache-semantics max-stale handling can disclose cross-user cached responses"},"relatedVulnerabilities":[{"id":"CVE-2026-93748","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93748","cwe":"CWE-524","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93748","date":"2026-10-07","epss":0.00531,"percentile":0.43085}],"urls":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623","https://github.com/kornelski/http-cache-semantics/issues/56","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93748","description":"http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.7","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-07","epss":0.0819,"percentile":0.94734}],"risk":0.40950000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."},"relatedVulnerabilities":[{"id":"CVE-2018-6952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-07","epss":0.0819,"percentile":0.94734}],"urls":["http://www.securityfocus.com/bid/103047","https://access.redhat.com/errata/RHSA-2019:2033","https://savannah.gnu.org/bugs/index.php?53133","https://security.gentoo.org/glsa/201904-17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8926","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"risk":0.40182000000000007,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user."},"relatedVulnerabilities":[{"id":"CVE-2026-8926","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-07","epss":0.00444,"percentile":0.36527}],"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."}]},{"artifact":{"id":"642df124d4347f65","cpes":["cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.11:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.11","type":"npm","version":"7.5.11","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.21"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r292-9mhp-454m","versionConstraint":"<=7.5.20 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.11"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-r292-9mhp-454m","fix":{"state":"fixed","versions":["7.5.21"],"available":[{"date":"2026-07-24","kind":"first-observed","version":"7.5.21"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73566","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-73566","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73566","date":"2026-10-07","epss":0.00531,"percentile":0.43064}],"risk":0.39825,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m","https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a","https://github.com/isaacs/node-tar/releases/tag/v7.5.21","https://nvd.nist.gov/vuln/detail/CVE-2026-73566"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r292-9mhp-454m","description":"node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection"},"relatedVulnerabilities":[{"id":"CVE-2026-73566","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73566","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-73566","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-73566","date":"2026-10-07","epss":0.00531,"percentile":0.43064}],"urls":["https://github.com/isaacs/node-tar/commit/631ae59121bf8fc8a22bbae35f074cb9b789cd4a","https://github.com/isaacs/node-tar/security/advisories/GHSA-r292-9mhp-454m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73566","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path header with thousands of slash-separated segments reaches this.filter(entry.path, entry) in Parser[CONSUMEHEADER] in src/parse.ts before Unpack[CHECKPATH] applies maxDepth, causing an uncatchable RangeError stack overflow that terminates asynchronous and streaming Node.js consumers. This issue is fixed in version 7.5.21."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"risk":0.39655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"risk":0.39655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"risk":0.39655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"risk":0.39655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"risk":0.39655,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables  B.2 or B.3 correctly: the latest Unicode codepoint attributes were used  instead of the specified Unicode 3.2.0. This behavior would cause  mismatches when processing domain names using IDNA 2003 (the \"idna\"  codec) and the in_table_b2() function of the \"stringprep\" module. This  only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding  behavior updated since Unicode 3.2.0."},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-07","epss":0.00721,"percentile":0.52498}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"risk":0.39039,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected.   Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected."},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-07","epss":0.00429,"percentile":0.35136}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63718","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63718","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-07","epss":0.00499,"percentile":0.4076}],"risk":0.37424999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.    This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-63718","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63718","cwe":"CWE-444","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63718","date":"2026-10-07","epss":0.00499,"percentile":0.4076}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/26"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63718","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-56153","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-56153","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-07","epss":0.00498,"percentile":0.40718}],"risk":0.3735,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-56153","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56153","cwe":"CWE-787","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-56153","date":"2026-10-07","epss":0.00498,"percentile":0.40718}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56153","description":"Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"e4af9d87fe6663fa","cpes":["cpe:2.3:a:jonschlinkert:picomatch:4.0.3:*:*:*:*:node.js:*:*"],"name":"picomatch","purl":"pkg:npm/picomatch@4.0.3","type":"npm","version":"4.0.3","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/picomatch/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/picomatch/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c2c7-rcm5-vvqj","versionConstraint":">=4.0.0,<4.0.4 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"picomatch","version":"4.0.3"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c2c7-rcm5-vvqj","fix":{"state":"fixed","versions":["4.0.4"],"available":[{"date":"2026-03-26","kind":"first-observed","version":"4.0.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33671","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33671","date":"2026-10-07","epss":0.00488,"percentile":0.40008}],"risk":0.366,"urls":["https://github.com/micromatch/picomatch/security/advisories/GHSA-c2c7-rcm5-vvqj","https://github.com/micromatch/picomatch/commit/5eceecd27543b8e056b9307d69e105ea03618a7d","https://nvd.nist.gov/vuln/detail/CVE-2026-33671"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c2c7-rcm5-vvqj","description":"Picomatch has a ReDoS vulnerability via extglob quantifiers"},"relatedVulnerabilities":[{"id":"CVE-2026-33671","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33671","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33671","date":"2026-10-07","epss":0.00488,"percentile":0.40008}],"urls":["https://github.com/micromatch/picomatch/commit/5eceecd27543b8e056b9307d69e105ea03618a7d","https://github.com/micromatch/picomatch/security/advisories/GHSA-c2c7-rcm5-vvqj"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33671","description":"Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users to supply glob patterns that are passed to `picomatch` for compilation or matching. In those cases, an attacker can cause excessive CPU consumption and block the Node.js event loop, resulting in a denial of service. Applications that only use trusted, developer-controlled glob patterns are much less likely to be exposed in a security-relevant way. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on their supported release line. If upgrading is not immediately possible, avoid passing untrusted glob patterns to `picomatch`. Possible mitigations include disabling extglob support for untrusted patterns by using `noextglob: true`, rejecting or sanitizing patterns containing nested extglobs or extglob quantifiers such as `+()` and `*()`, enforcing strict allowlists for accepted pattern syntax, running matching in an isolated worker or separate process with time and resource limits, and applying application-level request throttling and input validation for any endpoint that accepts glob patterns."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9080","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"risk":0.36556,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed."},"relatedVulnerabilities":[{"id":"CVE-2026-9080","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-07","epss":0.00494,"percentile":0.40446}],"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80255","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[{"id":"CVE-2026-80255","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-07","epss":0.00478,"percentile":0.39306}],"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63686","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63686","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-07","epss":0.00478,"percentile":0.39251}],"risk":0.35850000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63686","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63686","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63686","date":"2026-10-07","epss":0.00478,"percentile":0.39251}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/25"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63686","description":"A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73637","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73637","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-07","epss":0.00484,"percentile":0.39706}],"risk":0.35816,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73637","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73637","cwe":"CWE-416","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73637","date":"2026-10-07","epss":0.00484,"percentile":0.39706}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/28"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73637","description":"Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13608","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"risk":0.356855,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation."},"relatedVulnerabilities":[{"id":"CVE-2026-13608","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-07","epss":0.00479,"percentile":0.39352}],"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93546","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93546","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-07","epss":0.00436,"percentile":0.35884}],"risk":0.35534000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."},"relatedVulnerabilities":[{"id":"CVE-2026-93546","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93546","cwe":"CWE-190","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-93546","date":"2026-10-07","epss":0.00436,"percentile":0.35884}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/30"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93546","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-63045","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-63045","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-07","epss":0.00472,"percentile":0.38841}],"risk":0.35400000000000004,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-63045","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-63045","cwe":"CWE-284","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-63045","date":"2026-10-07","epss":0.00472,"percentile":0.38841}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/23"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-63045","description":"Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.0.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f886-m6hf-6m8v","versionConstraint":">=2.0.0,<2.0.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-f886-m6hf-6m8v","fix":{"state":"fixed","versions":["2.0.3"],"available":[{"date":"2026-03-27","kind":"first-observed","version":"2.0.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33750","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33750","date":"2026-10-07","epss":0.00613,"percentile":0.4771}],"risk":0.352475,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v","https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113","https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184","https://github.com/juliangruber/brace-expansion/issues/98","https://github.com/juliangruber/brace-expansion/pull/95","https://github.com/juliangruber/brace-expansion/pull/96","https://github.com/juliangruber/brace-expansion/pull/97","https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5","https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2","https://github.com/juliangruber/brace-expansion/commit/b9cacd9e55e7a1fa588fe4b7bb1159d52f1d902a","https://nvd.nist.gov/vuln/detail/CVE-2026-33750"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f886-m6hf-6m8v","description":"brace-expansion: Zero-step sequence causes process hang and memory exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-33750","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33750","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33750","date":"2026-10-07","epss":0.00613,"percentile":0.4771}],"urls":["https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L107-L113","https://github.com/juliangruber/brace-expansion/blob/daa71bcb4a30a2df9bcb7f7b8daaf2ab30e5794a/src/index.ts#L184","https://github.com/juliangruber/brace-expansion/commit/311ac0d54994158c0a384e286a7d6cbb17ee8ed5","https://github.com/juliangruber/brace-expansion/commit/7fd684f89fdde3549563d0a6522226a9189472a2","https://github.com/juliangruber/brace-expansion/commit/b9cacd9e55e7a1fa588fe4b7bb1159d52f1d902a","https://github.com/juliangruber/brace-expansion/issues/98","https://github.com/juliangruber/brace-expansion/pull/95","https://github.com/juliangruber/brace-expansion/pull/96","https://github.com/juliangruber/brace-expansion/pull/97","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-f886-m6hf-6m8v"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33750","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds and allocate heaps of memory. Versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13 fix the issue. As a workaround, sanitize strings passed to `expand()` to ensure a step value of `0` is not used."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.7&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2017-17740","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2017-17740","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-07","epss":0.07022,"percentile":0.94013}],"risk":0.3511,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."},"relatedVulnerabilities":[{"id":"CVE-2017-17740","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2017-17740","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2017-17740","date":"2026-10-07","epss":0.07022,"percentile":0.94013}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00053.html","http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00058.html","http://www.openldap.org/its/index.cgi/Incoming?id=8759","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2017-17740","description":"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46729","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-46729","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-07","epss":0.00468,"percentile":0.38515}],"risk":0.35100000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-46729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46729","cwe":"CWE-476","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-46729","date":"2026-10-07","epss":0.00468,"percentile":0.38515}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/13"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46729","description":"NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54873","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54873","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"risk":0.34650000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.  Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.  To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-54873","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54873","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54873","date":"2026-10-07","epss":0.00462,"percentile":0.38072}],"urls":["https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","description":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"risk":0.344005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"risk":0.344005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"risk":0.344005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"risk":0.344005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"risk":0.344005,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-07","epss":0.00643,"percentile":0.49227}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"a604db0b806d9b55","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"212a71fa16031fdf","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-69720","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-69720","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"risk":0.341955,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."},"relatedVulnerabilities":[{"id":"CVE-2025-69720","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-69720","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2025-69720","cwe":"CWE-120","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-69720","date":"2026-10-07","epss":0.00447,"percentile":0.36855}],"urls":["https://github.com/Cao-Wuhui/CVE-2025-69720","https://invisible-island.net/archives/ncurses/6.5/","https://invisible-island.net/ncurses/","https://marc.info/?l=ncurses-bug&m=176539968328570&w=2","https://marc.info/?l=ncurses-bug&m=176540731801330&w=2","https://marc.info/?l=ncurses-bug&m=176545557728083&w=2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-69720","description":"The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c."}]},{"artifact":{"id":"8023e330605becba","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/debian/dirmngr@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"e708db6544496117","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/debian/gnupg@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=gnupg2","type":"deb","version":"2.4.7-21+deb13u1","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"aecb683b9f0b939d","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.7-21\\+deb13u1:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/debian/gnupg-l10n@2.4.7-21%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=gnupg2","type":"deb","version":"2.4.7-21+deb13u1","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"222556b6ad068cc9","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/debian/gnupg-utils@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"4c977c82951f693d","cpes":["cpe:2.3:a:gpg:gpg:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/debian/gpg@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg.list"},{"path":"/var/lib/dpkg/info/gpg.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg.postinst"},{"path":"/var/lib/dpkg/info/gpg.postrm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg.postrm"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"4ac4029721ccdd3d","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/debian/gpg-agent@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"1444ab65c40a4def","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/debian/gpg-wks-client@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"d5ed9e46902b0669","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/debian/gpgconf@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"f63041d36162ac8a","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/debian/gpgsm@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"06849348ec2a380e","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.7-21\\+deb13u1\\+b5:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/debian/gpgv@2.4.7-21%2Bdeb13u1%2Bb5?arch=amd64&distro=debian-13.7&upstream=gnupg2%402.4.7-21%2Bdeb13u1","type":"deb","version":"2.4.7-21+deb13u1+b5","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2","version":"2.4.7-21+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-24882","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gnupg2","version":"2.4.7-21+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-24882","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"risk":0.3396600000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."},"relatedVulnerabilities":[{"id":"CVE-2026-24882","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.4,"impactScore":5.9,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"cve@mitre.org"},{"cve":"CVE-2026-24882","cwe":"CWE-121","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-24882","date":"2026-10-07","epss":0.00444,"percentile":0.36587}],"urls":["https://dev.gnupg.org/T8045","https://www.openwall.com/lists/oss-security/2026/01/27/8","https://access.redhat.com/errata/RHSA-2026:2719","https://access.redhat.com/errata/RHSA-2026:2753","https://access.redhat.com/security/cve/CVE-2026-24882","https://bugzilla.redhat.com/show_bug.cgi?id=2433464","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24882.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-24882","description":"In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys."}]},{"artifact":{"id":"e9d28bf4fecb65b4","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"8d18bdf2d28de8c0","cpes":["cpe:2.3:a:perl:perl:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"ec18de78d97e6b78","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9538","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9538","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"risk":0.33599999999999997,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.  _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.  A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."},"relatedVulnerabilities":[{"id":"CVE-2026-9538","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9538","cwe":"CWE-789","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-9538","date":"2026-10-07","epss":0.00448,"percentile":0.36945}],"urls":["https://github.com/jib/archive-tar-new/commit/f9af01426038e29d9578825a0cd3626946ab08c7.patch","https://metacpan.org/release/BINGOS/Archive-Tar-3.10/changes","http://www.openwall.com/lists/oss-security/2026/05/26/4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9538","description":"Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.\n\n_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.\n\nA crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size."}]},{"artifact":{"id":"642df124d4347f65","cpes":["cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.11:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.11","type":"npm","version":"7.5.11","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.18"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w8wr-v893-vjvp","versionConstraint":"<=7.5.17 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.11"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-w8wr-v893-vjvp","fix":{"state":"fixed","versions":["7.5.18"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.5.18"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59871","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59871","date":"2026-10-07","epss":0.00644,"percentile":0.49246}],"risk":0.33166,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp","https://nvd.nist.gov/vuln/detail/CVE-2026-59871","https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b","https://github.com/isaacs/node-tar/releases/tag/v7.5.18"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w8wr-v893-vjvp","description":"node-tar: Process crash via PAX numeric path type confusion"},"relatedVulnerabilities":[{"id":"CVE-2026-59871","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59871","cwe":"CWE-704","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59871","date":"2026-10-07","epss":0.00644,"percentile":0.49246}],"urls":["https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b","https://github.com/isaacs/node-tar/releases/tag/v7.5.18","https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59871","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-07","epss":0.00403,"percentile":0.32461}],"risk":0.32642999999999994,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-07","epss":0.00403,"percentile":0.32461}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-73636","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-73636","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-07","epss":0.00412,"percentile":0.33412}],"risk":0.32136000000000003,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.  Users are recommended to upgrade to version 2.4.69, which fixes this issue."},"relatedVulnerabilities":[{"id":"CVE-2026-73636","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-73636","cwe":"CWE-294","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-73636","date":"2026-10-07","epss":0.00412,"percentile":0.33412}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3184","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3184","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"risk":0.319815,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."},"relatedVulnerabilities":[{"id":"CVE-2026-3184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3184","cwe":"CWE-289","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-3184","date":"2026-10-07","epss":0.00621,"percentile":0.48123}],"urls":["https://access.redhat.com/errata/RHSA-2026:7180","https://access.redhat.com/security/cve/CVE-2026-3184","https://bugzilla.redhat.com/show_bug.cgi?id=2442570"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3184","description":"A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access."}]},{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56434","versionConstraint":">= 0.8.11, < 1.30.4||>= 1.31.0, < 1.31.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.3"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56434","versionConstraint":">= 0.8.11, < 1.30.4||>= 1.31.0, < 1.31.3 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56434","fix":{"state":"fixed","versions":["1.30.4","1.31.3"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"1.30.4"},{"date":"2026-07-21","kind":"first-observed","version":"1.31.3"}]},"cvss":[{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56434","cwe":"CWE-416","type":"Secondary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-56434","date":"2026-10-07","epss":0.00419,"percentile":0.34206}],"risk":0.312155,"urls":["https://my.f5.com/manage/s/article/K000162098"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56434","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an upstream server may be able to cause a use-after-free in the NGINX worker process. This issue may lead to limited modification of memory or a restart of the NGINX worker process.\n\nImpact:\nThis vulnerability may allow remote attackers to have limited control to modify memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84782","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84782","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"risk":0.30615,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.  Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.  CWE: CWE-125: Out-of-bounds Read  Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.  The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.  Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.  The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84782","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84782","cwe":"CWE-125","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84782","date":"2026-10-07","epss":0.0039,"percentile":0.31024}],"urls":["https://github.com/openssl/openssl/commit/906cf0ef1c85ca40ce69163e9086d6d3fe292943","https://github.com/openssl/openssl/commit/9f6b34422af7eb5dac61322e33dac1ae989fa628","https://github.com/openssl/openssl/commit/a383dafdd754eb5b22bf45e37e1bff9d07277a58","https://github.com/openssl/openssl/commit/d951e02ede8f6a6ff8150546db44b34f0518192c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84782","description":"Issue summary: The DTLS retransmission logic does not correctly handle\na handshake message write that is suspended part-way through.\nThe retransmitted message can be read past the message buffer and\nthe retransmission overwrites the internal state the suspended write\nneeds to resume correctly.\n\nImpact summary: The retransmitted message can disclose a heap memory\nto the peer as plaintext handshake data or cause a crash and a Denial\nof Service when the read reaches an unmapped memory region.\n\nCWE: CWE-125: Out-of-bounds Read\n\nDescription: DTLS handshake messages can be written out in multiple\nfragments, and a write can suspend mid-message (returning WANT_WRITE)\nif the underlying transport temporarily cannot accept more data. While\nsuch a write is suspended, the DTLS retransmission timer may\nindependently fire and ask the retransmission logic to resend an\nearlier, already-acknowledged-as-sent message from its retransmit\nqueue.\n\nThe retransmission logic reused the same internal buffer and position\ntracking as the message that was still being written, without\nresetting the position back to the start of the message being\nretransmitted. As a result the retransmission was read starting from\nwherever the suspended write had left off, producing a mislabelled\nmessage whose body was leftover bytes from the other, larger message\nstill in flight - content that was never meant to be sent at that\npoint, and which could run past the end of the allocated buffer.\n\nSeparately, even when the retransmission is positioned correctly,\nallowing it to run to completion while another write is suspended\noverwrites the same shared bookkeeping that the suspended write\ndepends on to resume. When the application later resumes the\nsuspended write (via a subsequent SSL_read(), SSL_write(),\nSSL_accept(), or SSL_connect() call), it finds that bookkeeping in a\nstate inconsistent with the message and aborts the process in\na debugging build.\n\nThe fix resets the retransmission's read position to the start of the\nmessage before resending, and skips retransmission entirely whenever a\nhandshake write is still suspended, deferring to the next call that\nresumes it instead.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-9545","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"risk":0.30600000000000005,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate.  When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information."},"relatedVulnerabilities":[{"id":"CVE-2026-9545","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-07","epss":0.00408,"percentile":0.32945}],"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-79768","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-79768","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-07","epss":0.0059,"percentile":0.46517}],"risk":0.30385,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-79768","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-79768","cwe":"CWE-55","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-79768","date":"2026-10-07","epss":0.0059,"percentile":0.46517}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/29"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-79768","description":"Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir)\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"risk":0.302755,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped.   This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration.   If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability.   Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied."},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-07","epss":0.00401,"percentile":0.32231}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84784","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-84784","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"risk":0.30225,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.  Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired.  The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame.  Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth.  [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-84784","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84784","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-84784","date":"2026-10-07","epss":0.00403,"percentile":0.32475}],"urls":["https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784","description":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8afff0c05acc6c7b","cpes":["cpe:2.3:a:proxy-addr:proxy-addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy-addr:proxy_addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy_addr:proxy-addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy_addr:proxy_addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy:proxy-addr:2.0.7:*:*:*:*:*:*:*","cpe:2.3:a:proxy:proxy_addr:2.0.7:*:*:*:*:*:*:*"],"name":"proxy-addr","purl":"pkg:npm/proxy-addr@2.0.7","type":"npm","version":"2.0.7","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/proxy-addr/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/proxy-addr/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.0.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jqcg-44mw-7w3h","versionConstraint":">=1.1.0,<2.0.8 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"proxy-addr","version":"2.0.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-jqcg-44mw-7w3h","fix":{"state":"fixed","versions":["2.0.8"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"2.0.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90711","cwe":"CWE-290","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-348","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-697","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-90711","date":"2026-10-07","epss":0.00332,"percentile":0.24328}],"risk":0.30046,"urls":["https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h","https://nvd.nist.gov/vuln/detail/CVE-2026-90711","https://github.com/jshttp/proxy-addr/commit/780911d84d18e2c5fa008ed0c0d387631ec11965","https://cna.openjsf.org/security-advisories.html","https://github.com/jshttp/proxy-addr/releases/tag/v2.0.8"],"severity":"Critical","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jqcg-44mw-7w3h","description":"proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet"},"relatedVulnerabilities":[{"id":"CVE-2026-90711","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90711","cwe":"CWE-290","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-348","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-90711","cwe":"CWE-697","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-90711","date":"2026-10-07","epss":0.00332,"percentile":0.24328}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90711","description":"proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet rather than the block it names. Because the socket peer then becomes trusted at hop 0, any unauthenticated client can supply an arbitrary X-Forwarded-For header and control the address the application reads, which defeats IP-based access control, rate limiting, geolocation, and audit logging. This is a fail-open regression introduced in version 1.1.0. The issue is fixed in proxy-addr 2.0.8, and users should upgrade to 2.0.8 or later. As a workaround, ensure any IPv4-mapped IPv6 trust subnet uses a prefix length of at least 97, or express the range in plain IPv4 notation."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12064","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"risk":0.29924999999999996,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error."},"relatedVulnerabilities":[{"id":"CVE-2026-12064","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-07","epss":0.00399,"percentile":0.32048}],"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."}]},{"artifact":{"id":"1f32975dfd37be95","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/debian/libpam-modules@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"cb7fdbb7b6a04bdc","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/debian/libpam-modules-bin@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"eb5873c5c35e21b8","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.7.0-5:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/debian/libpam-runtime@1.7.0-5?arch=all&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"1c6c7728b37b94de","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.7.0-5:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/debian/libpam0g@1.7.0-5?arch=amd64&distro=debian-13.7&upstream=pam","type":"deb","version":"1.7.0-5","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL-1","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54411","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pam","version":"1.7.0-5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54411","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"risk":0.2975,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."},"relatedVulnerabilities":[{"id":"CVE-2026-54411","cvss":[{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54411","cwe":"CWE-208","type":"Secondary","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}],"epss":[{"cve":"CVE-2026-54411","date":"2026-10-07","epss":0.005,"percentile":0.40857}],"urls":["https://cwe.mitre.org/data/definitions/208.html","https://github.com/linux-pam/linux-pam","https://github.com/linux-pam/linux-pam/blob/master/libpam/include/pam_inline.h","https://github.com/linux-pam/linux-pam/blob/master/modules/pam_userdb/pam_userdb.c#L327"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54411","description":"Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"risk":0.297,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.  libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key."},"relatedVulnerabilities":[{"id":"CVE-2026-8932","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-07","epss":0.00396,"percentile":0.31703}],"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."}]},{"artifact":{"id":"52238e88970d12b9","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/node-gyp/node_modules/undici/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/node-gyp/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rfgv-xxqx-mfg5","versionConstraint":">=6.7.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rfgv-xxqx-mfg5","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-07","epss":0.00394,"percentile":0.31437}],"risk":0.29550000000000004,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","https://nvd.nist.gov/vuln/detail/CVE-2026-19534","https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5","https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728","https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rfgv-xxqx-mfg5","description":"undici vulnerable to Denial of Service via unrequested WebSocket subprotocol"},"relatedVulnerabilities":[{"id":"CVE-2026-19534","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19534","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"cve":"CVE-2026-19534","cwe":"CWE-252","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-19534","date":"2026-10-07","epss":0.00394,"percentile":0.31437}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","description":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"risk":0.293035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.     This behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.     The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64  alphabet they are expecting or verify that their application would not be  affected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-07","epss":0.00569,"percentile":0.45371}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82209","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"risk":0.292805,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).  Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., `attacker.co.uk`)."},"relatedVulnerabilities":[{"id":"CVE-2026-82209","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-07","epss":0.00373,"percentile":0.29164}],"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-5435","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5435","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"risk":0.29156,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."},"relatedVulnerabilities":[{"id":"CVE-2026-5435","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5435","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-5435","date":"2026-10-07","epss":0.00394,"percentile":0.31478}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34033","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5435","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records."}]},{"artifact":{"id":"6f317725459bceed","cpes":["cpe:2.3:a:patrickjuchli:basic-ftp:5.3.1:*:*:*:*:node.js:*:*"],"name":"basic-ftp","purl":"pkg:npm/basic-ftp@5.3.1","type":"npm","version":"5.3.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/basic-ftp/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/basic-ftp/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c475-qrg2-pj4r","versionConstraint":"<=6.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"basic-ftp","version":"5.3.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-c475-qrg2-pj4r","fix":{"state":"fixed","versions":["6.2.1"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"6.2.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102990","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102990","date":"2026-10-07","epss":0.0037,"percentile":0.28818}],"risk":0.29045,"urls":["https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r","https://nvd.nist.gov/vuln/detail/CVE-2026-102990","https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9","https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c475-qrg2-pj4r","description":"basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)"},"relatedVulnerabilities":[{"id":"CVE-2026-102990","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102990","cwe":"CWE-1333","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102990","date":"2026-10-07","epss":0.0037,"percentile":0.28818}],"urls":["https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9","https://github.com/patrickjuchli/basic-ftp/releases/tag/v6.2.1","https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102990","description":"basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU time parsing a directory listing because the RE_LINE expression in src/parseListUnix.ts backtracks across adjacent variable-length owner and group fields when a long Unix-style line has a valid prefix but cannot satisfy the later size and date fields. parseList() selects a parser from the last nonblank line and then applies it to every line, so a normal final line can select the Unix parser while an earlier crafted line blocks the Node.js event loop and freezes the process. This issue is fixed in version 6.2.1."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47360","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-47360","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-07","epss":0.00386,"percentile":0.3051}],"risk":0.2895,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.        When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.      This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-47360","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47360","cwe":"CWE-200","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-47360","date":"2026-10-07","epss":0.00386,"percentile":0.3051}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/14"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47360","description":"Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.\n\n\n\n   \nWhen SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server.\n\n\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2008-3234","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2008-3234","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-07","epss":0.05773,"percentile":0.92892}],"risk":0.28865,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."},"relatedVulnerabilities":[{"id":"CVE-2008-3234","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":6.5,"impactScore":6.5,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2008-3234","cwe":"CWE-264","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2008-3234","date":"2026-10-07","epss":0.05773,"percentile":0.92892}],"urls":["http://www.securityfocus.com/bid/30276","https://exchange.xforce.ibmcloud.com/vulnerabilities/44037","https://www.exploit-db.com/exploits/6094"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2008-3234","description":"sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20796","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20796","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"risk":0.28785000000000005,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."},"relatedVulnerabilities":[{"id":"CVE-2018-20796","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20796","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20796","date":"2026-10-07","epss":0.05757,"percentile":0.92874}],"urls":["http://www.securityfocus.com/bid/107160","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141","https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://security.netapp.com/advisory/ntap-20190315-0002/","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20796","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80230","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"risk":0.27825,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[{"id":"CVE-2026-80230","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-07","epss":0.00371,"percentile":0.28975}],"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60002","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-60002","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-07","epss":0.003,"percentile":0.20776}],"risk":0.276,"urls":[],"severity":"Critical","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"},"relatedVulnerabilities":[{"id":"CVE-2026-60002","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":9.4,"impactScore":5.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60002","cwe":"CWE-416","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60002","date":"2026-10-07","epss":0.003,"percentile":0.20776}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60002","description":"ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)"}]},{"artifact":{"id":"f192cb8dc63f3eb4","cpes":["cpe:2.3:a:cpp-14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14","purl":"pkg:deb/debian/cpp-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/cpp-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"1580254f2d5cda2a","cpes":["cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14-x86-64-linux-gnu","purl":"pkg:deb/debian/cpp-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/cpp-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"bf427850ceb9b9cf","cpes":["cpe:2.3:a:g\\+\\+-14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14","purl":"pkg:deb/debian/g%2B%2B-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/g++-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"64cb91ba3690d600","cpes":["cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14-x86-64-linux-gnu","purl":"pkg:deb/debian/g%2B%2B-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/g++-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"1753e0ab4835d319","cpes":["cpe:2.3:a:gcc-14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14","purl":"pkg:deb/debian/gcc-14@14.2.0-19?arch=amd64&distro=debian-13.7","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/gcc-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"afc74f4635aa2de5","cpes":["cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-x86-64-linux-gnu","purl":"pkg:deb/debian/gcc-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/gcc-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"7475a27907fe4420","cpes":["cpe:2.3:a:libasan8:libasan8:14.2.0-19:*:*:*:*:*:*:*"],"name":"libasan8","purl":"pkg:deb/debian/libasan8@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libasan8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasan8:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libasan8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"4aef59838e786012","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"062249237978e3de","cpes":["cpe:2.3:a:libcc1-0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1-0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1_0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libcc1-0","purl":"pkg:deb/debian/libcc1-0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libcc1-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"ef5dd5e55126a732","cpes":["cpe:2.3:a:libgcc-14-dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14-dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-14-dev","purl":"pkg:deb/debian/libgcc-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libgcc-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"71d32d5417d636ce","cpes":["cpe:2.3:a:libgomp1:libgomp1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"81d0f863177c4ff2","cpes":["cpe:2.3:a:libhwasan0:libhwasan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libhwasan0","purl":"pkg:deb/debian/libhwasan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libhwasan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"30ada6cb82fd6f02","cpes":["cpe:2.3:a:libitm1:libitm1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libitm1","purl":"pkg:deb/debian/libitm1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libitm1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libitm1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libitm1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"d3f0e91aac2169e5","cpes":["cpe:2.3:a:liblsan0:liblsan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"liblsan0","purl":"pkg:deb/debian/liblsan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblsan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"2e7766dcd5ecb5f3","cpes":["cpe:2.3:a:libquadmath0:libquadmath0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libquadmath0","purl":"pkg:deb/debian/libquadmath0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libquadmath0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"0f0a43dbd793abf5","cpes":["cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++-14-dev","purl":"pkg:deb/debian/libstdc%2B%2B-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libstdc++-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"3faa4e2eb1e6610c","cpes":["cpe:2.3:a:libtsan2:libtsan2:14.2.0-19:*:*:*:*:*:*:*"],"name":"libtsan2","purl":"pkg:deb/debian/libtsan2@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libtsan2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"79fd96516c7017fa","cpes":["cpe:2.3:a:libubsan1:libubsan1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libubsan1","purl":"pkg:deb/debian/libubsan1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libubsan1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95619","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-95619","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"risk":0.27588,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."},"relatedVulnerabilities":[{"id":"CVE-2026-95619","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95619","cwe":"CWE-190","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-95619","date":"2026-10-07","epss":0.00363,"percentile":0.28083}],"urls":["https://access.redhat.com/errata/RHSA-2026:58503","https://access.redhat.com/errata/RHSA-2026:67275","https://access.redhat.com/security/cve/CVE-2026-95619","https://bugzilla.redhat.com/show_bug.cgi?id=2537811"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95619","description":"A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58415","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58415","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-07","epss":0.00533,"percentile":0.43194}],"risk":0.274495,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory    This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-58415","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58415","cwe":"CWE-552","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-58415","date":"2026-10-07","epss":0.00533,"percentile":0.43194}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/20"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58415","description":"Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20012","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2016-20012","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-07","epss":0.05326,"percentile":0.924}],"risk":0.26630000000000004,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"},"relatedVulnerabilities":[{"id":"CVE-2016-20012","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20012","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-20012","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-20012","date":"2026-10-07","epss":0.05326,"percentile":0.924}],"urls":["https://github.com/openssh/openssh-portable/blob/d0fffc88c8fe90c1815c6f4097bc8cbcabc0f3dd/auth2-pubkey.c#L261-L265","https://github.com/openssh/openssh-portable/pull/270","https://github.com/openssh/openssh-portable/pull/270#issuecomment-920577097","https://github.com/openssh/openssh-portable/pull/270#issuecomment-943909185","https://rushter.com/blog/public-ssh-keys/","https://security.netapp.com/advisory/ntap-20211014-0005/","https://utcc.utoronto.ca/~cks/space/blog/tech/SSHKeysAreInfoLeak","https://www.openwall.com/lists/oss-security/2018/08/24/1"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20012","description":"OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product"}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.7&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2015-3276","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2015-3276","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-07","epss":0.05269,"percentile":0.92341}],"risk":0.26345,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."},"relatedVulnerabilities":[{"id":"CVE-2015-3276","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2015-3276","date":"2026-10-07","epss":0.05269,"percentile":0.92341}],"urls":["http://rhn.redhat.com/errata/RHSA-2015-2131.html","http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html","http://www.securitytracker.com/id/1034221","https://bugzilla.redhat.com/show_bug.cgi?id=1238322"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2015-3276","description":"The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors."}]},{"artifact":{"id":"b958288bb0c2bb20","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.1.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.1.0","type":"npm","version":"10.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v2v4-37r5-5v8g","versionConstraint":"<=10.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-v2v4-37r5-5v8g","fix":{"state":"fixed","versions":["10.1.1"],"available":[{"date":"2026-05-06","kind":"first-observed","version":"10.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42338","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42338","cwe":"CWE-79","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42338","date":"2026-10-07","epss":0.00511,"percentile":0.41715}],"risk":0.26316500000000004,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g","https://nvd.nist.gov/vuln/detail/CVE-2026-42338"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v2v4-37r5-5v8g","description":"ip-address has XSS in Address6 HTML-emitting methods"},"relatedVulnerabilities":[{"id":"CVE-2026-42338","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42338","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-42338","cwe":"CWE-79","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42338","date":"2026-10-07","epss":0.00511,"percentile":0.41715}],"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:35841","https://access.redhat.com/errata/RHSA-2026:35842","https://access.redhat.com/errata/RHSA-2026:35891","https://access.redhat.com/errata/RHSA-2026:35892","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:39246","https://access.redhat.com/errata/RHSA-2026:39868","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41947","https://access.redhat.com/errata/RHSA-2026:44237","https://access.redhat.com/errata/RHSA-2026:44263","https://access.redhat.com/errata/RHSA-2026:44267","https://access.redhat.com/errata/RHSA-2026:51200","https://access.redhat.com/errata/RHSA-2026:52399","https://access.redhat.com/errata/RHSA-2026:56928","https://access.redhat.com/errata/RHSA-2026:57590","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62335","https://access.redhat.com/errata/RHSA-2026:62336","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-42338","https://bugzilla.redhat.com/show_bug.cgi?id=2476810","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42338","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=2.0.0,<2.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["2.1.6"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-07","epss":0.0035,"percentile":0.26576}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-07","epss":0.0035,"percentile":0.26576}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"04e02497b9a7e6b4","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/brace-expansion/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qhr7-859c-m2p7","versionConstraint":">=4.0.0,<5.0.11 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-qhr7-859c-m2p7","fix":{"state":"fixed","versions":["5.0.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-07","epss":0.0035,"percentile":0.26576}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7","https://nvd.nist.gov/vuln/detail/CVE-2026-102278","https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qhr7-859c-m2p7","description":"brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102278","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102278","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102278","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102278","date":"2026-10-07","epss":0.0035,"percentile":0.26576}],"urls":["https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b","https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c","https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102278","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled recursion for nested brace alternatives and single-part sets. deeply nested brace groups supplied as an untrusted pattern. expand_ is affected. expand is affected. Comma members is affected. Single set is affected. native stack exhaustion during nested sub-expansion. process-terminating denial of service. This issue is fixed in versions 1.1.20, 2.1.6, 3.0.8, and 5.0.11."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.5"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=2.0.0,<2.1.5 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["2.1.5"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.1.5"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-07","epss":0.0035,"percentile":0.26575}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-07","epss":0.0035,"percentile":0.26575}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"04e02497b9a7e6b4","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/brace-expansion/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6j4f-fj2g-mc7p","versionConstraint":">=4.0.0,<5.0.10 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-6j4f-fj2g-mc7p","fix":{"state":"fixed","versions":["5.0.10"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-07","epss":0.0035,"percentile":0.26575}],"risk":0.2625,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p","https://nvd.nist.gov/vuln/detail/CVE-2026-102276","https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6j4f-fj2g-mc7p","description":"brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-102276","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102276","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102276","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102276","date":"2026-10-07","epss":0.0035,"percentile":0.26575}],"urls":["https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc","https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c","https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc","https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102276","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns containing many comma-separated brace groups trigger the recursive path, while the large array triggers the argument-array path without deep recursion. These paths cause recursive and argument-array native stack exhaustion before max or maxLength can limit output, potentially terminating the Node.js process in a process-terminating denial of service. This issue is fixed in versions 1.1.19, 2.1.5, 3.0.7, and 5.0.10."}]},{"artifact":{"id":"5e62182cb9eb8100","cpes":["cpe:2.3:a:pacote:pacote:19.0.2:*:*:*:*:*:*:*"],"name":"pacote","purl":"pkg:npm/pacote@19.0.2","type":"npm","version":"19.0.2","language":"javascript","licenses":["ISC"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/pacote/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/pacote/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w4pp-8pjf-rmxw","versionConstraint":">=11.2.7,<21.5.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"pacote","version":"19.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-w4pp-8pjf-rmxw","fix":{"state":"fixed","versions":["21.5.1"],"available":[{"date":"2026-08-27","kind":"first-observed","version":"21.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9496","cwe":"CWE-1333","type":"Secondary","source":"report@snyk.io"},{"cve":"CVE-2026-9496","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-9496","date":"2026-10-07","epss":0.00346,"percentile":0.26018}],"risk":0.26123,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-9496","https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/util/add-git-sha.js%23L2C1-L13C2","https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16874025","https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084","https://github.com/npm/pacote/commit/627a7dc1a214d857472a13b48e42559c75288c9e","https://github.com/npm/pacote/commit/ce804fb1647fe1699b2f87efd01ea9f4efed8508","https://github.com/npm/pacote/releases/tag/v21.5.1","https://github.com/npm/pacote/releases/tag/v22.0.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w4pp-8pjf-rmxw","description":"pacote is vulnerable to Denial of Service (DoS) via the addGitSha function"},"relatedVulnerabilities":[{"id":"CVE-2026-9496","cvss":[{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9496","cwe":"CWE-1333","type":"Secondary","source":"report@snyk.io"},{"cve":"CVE-2026-9496","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-9496","date":"2026-10-07","epss":0.00346,"percentile":0.26018}],"urls":["https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/util/add-git-sha.js%23L2C1-L13C2","https://github.com/npm/pacote/commit/ce804fb1647fe1699b2f87efd01ea9f4efed8508","https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16874025","https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9496","description":"Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic,  causing excessive CPU consumption and potentially stalling or crashing the process."}]},{"artifact":{"id":"0a736958895d8985","cpes":["cpe:2.3:a:pacote:pacote:20.0.1:*:*:*:*:*:*:*"],"name":"pacote","purl":"pkg:npm/pacote@20.0.1","type":"npm","version":"20.0.1","language":"javascript","licenses":["ISC"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/@npmcli/metavuln-calculator/node_modules/pacote/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/@npmcli/metavuln-calculator/node_modules/pacote/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"21.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w4pp-8pjf-rmxw","versionConstraint":">=11.2.7,<21.5.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"pacote","version":"20.0.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-w4pp-8pjf-rmxw","fix":{"state":"fixed","versions":["21.5.1"],"available":[{"date":"2026-08-27","kind":"first-observed","version":"21.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9496","cwe":"CWE-1333","type":"Secondary","source":"report@snyk.io"},{"cve":"CVE-2026-9496","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-9496","date":"2026-10-07","epss":0.00346,"percentile":0.26018}],"risk":0.26123,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-9496","https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/util/add-git-sha.js%23L2C1-L13C2","https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16874025","https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084","https://github.com/npm/pacote/commit/627a7dc1a214d857472a13b48e42559c75288c9e","https://github.com/npm/pacote/commit/ce804fb1647fe1699b2f87efd01ea9f4efed8508","https://github.com/npm/pacote/releases/tag/v21.5.1","https://github.com/npm/pacote/releases/tag/v22.0.0"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w4pp-8pjf-rmxw","description":"pacote is vulnerable to Denial of Service (DoS) via the addGitSha function"},"relatedVulnerabilities":[{"id":"CVE-2026-9496","cvss":[{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"report@snyk.io","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9496","cwe":"CWE-1333","type":"Secondary","source":"report@snyk.io"},{"cve":"CVE-2026-9496","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-9496","date":"2026-10-07","epss":0.00346,"percentile":0.26018}],"urls":["https://github.com/npm/pacote/blob/9d7459440826ab4cf962ef98d8f3fd0c4d464b5c/lib/util/add-git-sha.js%23L2C1-L13C2","https://github.com/npm/pacote/commit/ce804fb1647fe1699b2f87efd01ea9f4efed8508","https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-16874025","https://security.snyk.io/vuln/SNYK-JS-PACOTE-8225084"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9496","description":"Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic,  causing excessive CPU consumption and potentially stalling or crashing the process."}]},{"artifact":{"id":"e4af9d87fe6663fa","cpes":["cpe:2.3:a:jonschlinkert:picomatch:4.0.3:*:*:*:*:node.js:*:*"],"name":"picomatch","purl":"pkg:npm/picomatch@4.0.3","type":"npm","version":"4.0.3","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/picomatch/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/picomatch/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.0.4"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3v7f-55p6-f55p","versionConstraint":">=4.0.0,<4.0.4 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"picomatch","version":"4.0.3"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3v7f-55p6-f55p","fix":{"state":"fixed","versions":["4.0.4"],"available":[{"date":"2026-03-26","kind":"first-observed","version":"4.0.4"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33672","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33672","date":"2026-10-07","epss":0.00507,"percentile":0.41346}],"risk":0.26110500000000003,"urls":["https://github.com/micromatch/picomatch/security/advisories/GHSA-3v7f-55p6-f55p","https://github.com/micromatch/picomatch/commit/4516eb521f13a46b2fe1a1d2c9ef6b20ddc0e903","https://nvd.nist.gov/vuln/detail/CVE-2026-33672"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3v7f-55p6-f55p","description":"Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching"},"relatedVulnerabilities":[{"id":"CVE-2026-33672","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33672","cwe":"CWE-1321","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-33672","date":"2026-10-07","epss":0.00507,"percentile":0.41346}],"urls":["https://github.com/micromatch/picomatch/commit/4516eb521f13a46b2fe1a1d2c9ef6b20ddc0e903","https://github.com/micromatch/picomatch/security/advisories/GHSA-3v7f-55p6-f55p"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33672","description":"Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:constructor:]]`) can reference inherited method names. These methods are implicitly converted to strings and injected into the generated regular expression. This leads to incorrect glob matching behavior (integrity impact), where patterns may match unintended filenames. The issue does not enable remote code execution, but it can cause security-relevant logic errors in applications that rely on glob matching for filtering, validation, or access control. All users of affected `picomatch` versions that process untrusted or user-controlled glob patterns are potentially impacted. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on their supported release line. If upgrading is not immediately possible, avoid passing untrusted glob patterns to picomatch. Possible mitigations include sanitizing or rejecting untrusted glob patterns, especially those containing POSIX character classes like `[[:...:]]`; avoiding the use of POSIX bracket expressions if user input is involved; and manually patching the library by modifying `POSIX_REGEX_SOURCE` to use a null prototype."}]},{"artifact":{"id":"642df124d4347f65","cpes":["cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.11:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.11","type":"npm","version":"7.5.11","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.17"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gvwx-54wh-qm9j","versionConstraint":"<=7.5.16 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.11"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-gvwx-54wh-qm9j","fix":{"state":"fixed","versions":["7.5.17"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"7.5.17"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59875","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59875","date":"2026-10-07","epss":0.00507,"percentile":0.41301}],"risk":0.26110500000000003,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j","https://nvd.nist.gov/vuln/detail/CVE-2026-59875","https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3","https://github.com/isaacs/node-tar/releases/tag/v7.5.17"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gvwx-54wh-qm9j","description":"node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records"},"relatedVulnerabilities":[{"id":"CVE-2026-59875","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59875","cwe":"CWE-248","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59875","date":"2026-10-07","epss":0.00507,"percentile":0.41301}],"urls":["https://github.com/isaacs/node-tar/commit/7a635c29f5edbf083557374d43984273ecfed5b3","https://github.com/isaacs/node-tar/releases/tag/v7.5.17","https://github.com/isaacs/node-tar/security/advisories/GHSA-gvwx-54wh-qm9j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59875","description":"node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17."}]},{"artifact":{"id":"6c23b5fbc804d426","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/debian/python3-pip-whl@25.1.1%2Bdfsg-1?arch=all&distro=debian-13.7&upstream=python-pip","type":"deb","version":"25.1.1+dfsg-1","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-8869","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python-pip","version":"25.1.1+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-8869","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8869","date":"2026-10-07","epss":0.00469,"percentile":0.38607}],"risk":0.255605,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-8869","description":"When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a \"fixed\" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.  Note that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706 and therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706 then pip doesn't use the \"vulnerable\" fallback code.  Mitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12), applying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice."},"relatedVulnerabilities":[{"id":"CVE-2025-8869","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-8869","date":"2026-10-07","epss":0.00469,"percentile":0.38607}],"urls":["https://github.com/pypa/pip/pull/13550","https://mail.python.org/archives/list/security-announce@python.org/thread/IF5A3GCJY3VH7BVHJKOWOJFKTW7VFQEN/","https://lists.debian.org/debian-lts-announce/2025/10/msg00028.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-8869","description":"When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706.\nNote that upgrading pip to a \"fixed\" version for this vulnerability doesn't fix all known vulnerabilities that are remediated by using a Python version that implements PEP 706.\n\nNote that this is a vulnerability in pip's fallback implementation of tar extraction for Python versions that don't implement PEP 706\nand therefore are not secure to all vulnerabilities in the Python 'tarfile' module. If you're using a Python version that implements PEP 706\nthen pip doesn't use the \"vulnerable\" fallback code.\n\nMitigations include upgrading to a version of pip that includes the fix, upgrading to a Python version that implements PEP 706 (Python >=3.9.17, >=3.10.12, >=3.11.4, or >=3.12),\napplying the linked patch, or inspecting source distributions (sdists) before installation as is already a best-practice."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6238","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6238","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"risk":0.2553,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.  These functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."},"relatedVulnerabilities":[{"id":"CVE-2026-6238","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6238","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6238","date":"2026-10-07","epss":0.00444,"percentile":0.36526}],"urls":["https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u","https://sourceware.org/bugzilla/show_bug.cgi?id=34069","https://cert-portal.siemens.com/productcert/html/ssa-082556.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6238","description":"The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\n\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"risk":0.2552,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.  Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.  Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-07","epss":0.00464,"percentile":0.3816}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3jxr-9vmj-r5cp","versionConstraint":">=2.0.0,<2.1.2 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3jxr-9vmj-r5cp","fix":{"state":"fixed","versions":["2.1.2"],"available":[{"date":"2026-07-21","kind":"first-observed","version":"2.1.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13149","cwe":"CWE-400","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"},{"cve":"CVE-2026-13149","cwe":"CWE-407","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"}],"epss":[{"cve":"CVE-2026-13149","date":"2026-10-07","epss":0.00364,"percentile":0.28117}],"risk":0.25479999999999997,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-3jxr-9vmj-r5cp","https://nvd.nist.gov/vuln/detail/CVE-2026-13149","https://github.com/juliangruber/brace-expansion/pull/122","https://github.com/juliangruber/brace-expansion/pull/123","https://github.com/juliangruber/brace-expansion/commit/835d6be91201122d9adffb0c0c8c094189ace265","https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754","https://github.com/juliangruber/brace-expansion/commit/d74e63030c012e3b7ae81657b8d665619cd51b95","https://github.com/juliangruber/brace-expansion/releases/tag/v1.1.16","https://github.com/juliangruber/brace-expansion/releases/tag/v2.1.2","https://github.com/juliangruber/brace-expansion/releases/tag/v5.0.7","https://www.npmjs.com/package/brace-expansion"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3jxr-9vmj-r5cp","description":"brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups"},"relatedVulnerabilities":[{"id":"CVE-2026-13149","cvss":[{"type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber","metrics":{"baseScore":7.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13149","cwe":"CWE-400","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"},{"cve":"CVE-2026-13149","cwe":"CWE-407","type":"Secondary","source":"22e2d327-25fe-45d7-9f0c-dcd23b7108df"}],"epss":[{"cve":"CVE-2026-13149","date":"2026-10-07","epss":0.00364,"percentile":0.28117}],"urls":["https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754","https://www.npmjs.com/package/brace-expansion"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13149","description":"brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work."}]},{"artifact":{"id":"6c23b5fbc804d426","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/debian/python3-pip-whl@25.1.1%2Bdfsg-1?arch=all&distro=debian-13.7&upstream=python-pip","type":"deb","version":"25.1.1+dfsg-1","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8643","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python-pip","version":"25.1.1+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8643","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-07","epss":0.00466,"percentile":0.38306}],"risk":0.24465000000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8643","description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory."},"relatedVulnerabilities":[{"id":"CVE-2026-8643","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8,"impactScore":5.9,"exploitabilityScore":2.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-8643","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-8643","date":"2026-10-07","epss":0.00466,"percentile":0.38306}],"urls":["https://github.com/pypa/pip/pull/14000","https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/","http://www.openwall.com/lists/oss-security/2026/06/01/5","https://access.redhat.com/errata/RHSA-2026:33313","https://access.redhat.com/errata/RHSA-2026:34374","https://access.redhat.com/errata/RHSA-2026:34456","https://access.redhat.com/errata/RHSA-2026:34739","https://access.redhat.com/errata/RHSA-2026:34740","https://access.redhat.com/errata/RHSA-2026:34741","https://access.redhat.com/errata/RHSA-2026:34748","https://access.redhat.com/errata/RHSA-2026:34749","https://access.redhat.com/errata/RHSA-2026:34750","https://access.redhat.com/errata/RHSA-2026:34752","https://access.redhat.com/errata/RHSA-2026:34756","https://access.redhat.com/errata/RHSA-2026:34758","https://access.redhat.com/errata/RHSA-2026:34760","https://access.redhat.com/errata/RHSA-2026:34765","https://access.redhat.com/errata/RHSA-2026:34772","https://access.redhat.com/errata/RHSA-2026:34773","https://access.redhat.com/errata/RHSA-2026:34774","https://access.redhat.com/errata/RHSA-2026:34775","https://access.redhat.com/errata/RHSA-2026:34776","https://access.redhat.com/errata/RHSA-2026:34777","https://access.redhat.com/errata/RHSA-2026:34778","https://access.redhat.com/errata/RHSA-2026:34780","https://access.redhat.com/errata/RHSA-2026:34891","https://access.redhat.com/errata/RHSA-2026:36193","https://access.redhat.com/errata/RHSA-2026:36315","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37283","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42144","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:50479","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:56347","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/security/cve/CVE-2026-8643","https://bugzilla.redhat.com/show_bug.cgi?id=2460927","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8643","description":"pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory."}]},{"artifact":{"id":"ca88752821693d8d","cpes":["cpe:2.3:a:patch:patch:2.8-2:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/debian/patch@2.8-2?arch=amd64&distro=debian-13.7","type":"deb","version":"2.8-2","language":"","licenses":["GPL-3","GPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2010-4651","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"patch","version":"2.8-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4651","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-07","epss":0.04874,"percentile":0.9182}],"risk":0.2437,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."},"relatedVulnerabilities":[{"id":"CVE-2010-4651","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4651","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4651","date":"2026-10-07","epss":0.04874,"percentile":0.9182}],"urls":["http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1","http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.html","http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.html","http://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.html","http://openwall.com/lists/oss-security/2011/01/05/10","http://openwall.com/lists/oss-security/2011/01/06/19","http://openwall.com/lists/oss-security/2011/01/06/20","http://openwall.com/lists/oss-security/2011/01/06/21","http://secunia.com/advisories/43663","http://secunia.com/advisories/43677","http://support.apple.com/kb/HT4723","http://www.securityfocus.com/bid/46768","http://www.vupen.com/english/advisories/2011/0600","https://bugzilla.redhat.com/show_bug.cgi?id=667529"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4651","description":"Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8286","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"risk":0.24101999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not."},"relatedVulnerabilities":[{"id":"CVE-2026-8286","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-07","epss":0.00309,"percentile":0.21789}],"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"risk":0.22999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-07","epss":0.00422,"percentile":0.34449}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"6c5c6b3dadd72c19","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/ip-address/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-2vr4-cq9g-pvrc","versionConstraint":">=10.2.0,<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-2vr4-cq9g-pvrc","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-07","epss":0.00386,"percentile":0.3051}],"risk":0.22967,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc","https://nvd.nist.gov/vuln/detail/CVE-2026-101910","https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-2vr4-cq9g-pvrc","description":"ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass"},"relatedVulnerabilities":[{"id":"CVE-2026-101910","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101910","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101910","date":"2026-10-07","epss":0.00386,"percentile":0.3051}],"urls":["https://github.com/beaugunderson/ip-address/commit/ab3dc88bcf5374344168a2ba075ca7ac4ff257f8","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-2vr4-cq9g-pvrc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101910","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does not recognize the NAT64 local-use range 64:ff9b:1::/48. Applications that combine isPrivate, isLoopback, and isLinkLocal for a trust-boundary decision can treat an internal IPv4 destination encoded through that range as external. Exploitation depends on a server network using an operator-selected NAT64 prefix within the local-use range. A successful bypass can cross the intended network trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19499","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19499","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"risk":0.22572,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.  Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.  At the time of publication, no network-facing application impact is known."},"relatedVulnerabilities":[{"id":"CVE-2026-19499","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","metrics":{"baseScore":7.7,"impactScore":5.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19499","cwe":"CWE-122","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19499","date":"2026-10-07","epss":0.00297,"percentile":0.20485}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34510","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0017"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19499","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-80489","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-80489","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."},"relatedVulnerabilities":[{"id":"CVE-2026-80489","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80489","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-80489","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34568","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0020"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80489","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117."}]},{"artifact":{"id":"52238e88970d12b9","cpes":["cpe:2.3:a:nodejs:undici:6.28.0:*:*:*:*:node.js:*:*"],"name":"undici","purl":"pkg:npm/undici@6.28.0","type":"npm","version":"6.28.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/node-gyp/node_modules/undici/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/node-gyp/node_modules/undici/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"6.28.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3wwx-pv8p-q78v","versionConstraint":">=6.25.0,<6.28.1 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"undici","version":"6.28.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-3wwx-pv8p-q78v","fix":{"state":"fixed","versions":["6.28.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"6.28.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"risk":0.22454000000000002,"urls":["https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v","https://nvd.nist.gov/vuln/detail/CVE-2026-85024","https://github.com/nodejs/undici/commit/07c60d9c7099a910451244afe42861bbdbdd974c","https://github.com/nodejs/undici/commit/4411a238a98e8791da5fff10cc9e3578a7668ed6","https://github.com/nodejs/undici/commit/63cf698b611fecc6ee0a17b185b930051e4b982f","https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/releases/tag/v6.28.1","https://github.com/nodejs/undici/releases/tag/v7.29.1","https://github.com/nodejs/undici/releases/tag/v8.10.2"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3wwx-pv8p-q78v","description":"undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression"},"relatedVulnerabilities":[{"id":"CVE-2026-85024","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85024","cwe":"CWE-248","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-85024","date":"2026-10-07","epss":0.00412,"percentile":0.33385}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85024","description":"undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77117","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-77117","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"risk":0.22454000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.  Some SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."},"relatedVulnerabilities":[{"id":"CVE-2026-77117","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77117","cwe":"CWE-835","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-77117","date":"2026-10-07","epss":0.00412,"percentile":0.33383}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34556","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0019"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77117","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-55654","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-55654","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55654","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-55654","date":"2026-10-07","epss":0.00652,"percentile":0.4965}],"risk":0.21841999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-55654","description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service."},"relatedVulnerabilities":[{"id":"CVE-2026-55654","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-55654","cwe":"CWE-125","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-55654","date":"2026-10-07","epss":0.00652,"percentile":0.4965}],"urls":["https://access.redhat.com/errata/RHSA-2026:36759","https://access.redhat.com/errata/RHSA-2026:47756","https://access.redhat.com/errata/RHSA-2026:47757","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/security/cve/CVE-2026-55654","https://bugzilla.redhat.com/show_bug.cgi?id=2462493"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-55654","description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service."}]},{"artifact":{"id":"b958288bb0c2bb20","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.1.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.1.0","type":"npm","version":"10.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpw4-54j3-4h4q","versionConstraint":"<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rpw4-54j3-4h4q","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-07","epss":0.00386,"percentile":0.30511}],"risk":0.21809,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q","https://nvd.nist.gov/vuln/detail/CVE-2026-101913","https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpw4-54j3-4h4q","description":"ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts"},"relatedVulnerabilities":[{"id":"CVE-2026-101913","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-07","epss":0.00386,"percentile":0.30511}],"urls":["https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101913","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"6c5c6b3dadd72c19","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/ip-address/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.5.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rpw4-54j3-4h4q","versionConstraint":"<=10.5.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rpw4-54j3-4h4q","fix":{"state":"fixed","versions":["10.5.1"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"10.5.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-07","epss":0.00386,"percentile":0.30511}],"risk":0.21809,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q","https://nvd.nist.gov/vuln/detail/CVE-2026-101913","https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rpw4-54j3-4h4q","description":"ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts"},"relatedVulnerabilities":[{"id":"CVE-2026-101913","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101913","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101913","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101913","date":"2026-10-07","epss":0.00386,"percentile":0.30511}],"urls":["https://github.com/beaugunderson/ip-address/commit/d03e960c7cc3179ef25c8a44b4f94dd499625546","https://github.com/beaugunderson/ip-address/releases/tag/v10.5.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-rpw4-54j3-4h4q"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101913","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlled address elsewhere in fe80::/10 can therefore pass a trust-boundary check that relies on isLinkLocal. The same address is identified as link-local by getType and getScope, exposing the inconsistent classification. A successful bypass can reach an on-link host outside the intended trust boundary. This issue is fixed in version 10.5.1."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76956","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76956","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-07","epss":0.00287,"percentile":0.19484}],"risk":0.21525,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."},"relatedVulnerabilities":[{"id":"CVE-2026-76956","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76956","cwe":"CWE-394","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-76956","date":"2026-10-07","epss":0.00287,"percentile":0.19484}],"urls":["https://github.com/libexpat/libexpat/pull/1326","https://github.com/libexpat/libexpat/pull/1329"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76956","description":"In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content."}]},{"artifact":{"id":"b75bf6aa8d5be733","cpes":["cpe:2.3:a:cryptography.io:cryptography:48.0.0:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:48.0.0:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@48.0.0","type":"python","version":"48.0.0","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/METADATA","layerID":"sha256:88df3601988d6f0f90f6145bed05fd6f8badc8172b4d2c6eb12f91d30721378d","accessPath":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/RECORD","layerID":"sha256:88df3601988d6f0f90f6145bed05fd6f8badc8172b4d2c6eb12f91d30721378d","accessPath":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"50.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g6cj-pr64-35w5","versionConstraint":">=44.0.0,<50.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"48.0.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-g6cj-pr64-35w5","fix":{"state":"fixed","versions":["50.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"50.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69247","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69247","cwe":"CWE-209","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69247","date":"2026-10-07","epss":0.00274,"percentile":0.18176}],"risk":0.21508999999999995,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g6cj-pr64-35w5","description":"cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing"},"relatedVulnerabilities":[{"id":"CVE-2026-69247","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69247","cwe":"CWE-208","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-69247","cwe":"CWE-209","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69247","date":"2026-10-07","epss":0.00274,"percentile":0.18176}],"urls":["https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f","https://github.com/pyca/cryptography/pull/15369","https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69247","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0."}]},{"artifact":{"id":"310cafbbd5abd891","cpes":["cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector-parser:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*"],"name":"postcss-selector-parser","purl":"pkg:npm/postcss-selector-parser@7.1.1","type":"npm","version":"7.1.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.1.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rj75-hqrm-r3gf","versionConstraint":"<7.1.6 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"postcss-selector-parser","version":"7.1.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-rj75-hqrm-r3gf","fix":{"state":"fixed","versions":["7.1.6"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"7.1.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-07","epss":0.00394,"percentile":0.31403}],"risk":0.21473,"urls":["https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf","https://nvd.nist.gov/vuln/detail/CVE-2026-104844","https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rj75-hqrm-r3gf","description":"PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion"},"relatedVulnerabilities":[{"id":"CVE-2026-104844","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-104844","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-104844","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-104844","date":"2026-10-07","epss":0.00394,"percentile":0.31403}],"urls":["https://github.com/postcss/postcss-selector-parser/commit/62b191792df0a0bc56062e5a875bc74aae2a51cd","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.6","https://github.com/postcss/postcss-selector-parser/security/advisories/GHSA-rj75-hqrm-r3gf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-104844","description":"PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a flat selector as one word token carrying many class or ID indexes because period and hash characters are not tokenizer word delimiters. The uniqs() deduplication and per-index class and ID membership checks repeatedly scan the class and ID index arrays, while a separate Sass-interpolation filtering pass also performs repeated linear scanning. Together, these passes make parsing quadratic in the number of indexes and allow a crafted selector to occupy a synchronous parser thread. The maxNestingDepth guard does not mitigate the issue because the hostile selector can have zero nesting depth. Only consumers that synchronously parse untrusted selectors in an exposed request path are affected; ordinary build-time parsing of trusted sources is not affected. This issue is fixed in version 7.1.6."}]},{"artifact":{"id":"5639ec83ccf64c26","cpes":["cpe:2.3:a:curl:curl:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:deb/debian/curl@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/curl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/curl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/curl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/curl.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"9e5beaf1197f535a","cpes":["cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64-gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64_gnutls:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64-gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libcurl3t64:libcurl3t64_gnutls:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl3t64-gnutls","purl":"pkg:deb/debian/libcurl3t64-gnutls@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl3t64-gnutls/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libcurl3t64-gnutls/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcurl3t64-gnutls:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"2b5843b2b58d0a1b","cpes":["cpe:2.3:a:libcurl4t64:libcurl4t64:8.14.1-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libcurl4t64","purl":"pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=curl","type":"deb","version":"8.14.1-2+deb13u5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","BSD-4-Clause-UC","FSFULLR","GPL-2","GPL-2+","GPL-3+","ISC","OLDAP-2.8","X11","curl"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libcurl4t64/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libcurl4t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libcurl4t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"curl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8458","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"curl","version":"8.14.1-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"risk":0.213325,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different \"services\".  libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.  When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services."},"relatedVulnerabilities":[{"id":"CVE-2026-8458","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-07","epss":0.00371,"percentile":0.28977}],"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-5704","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-5704","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-07","epss":0.00401,"percentile":0.32227}],"risk":0.210525,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."},"relatedVulnerabilities":[{"id":"CVE-2026-5704","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5,"impactScore":3.6,"exploitabilityScore":1.4},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5704","cwe":"CWE-434","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-5704","date":"2026-10-07","epss":0.00401,"percentile":0.32227}],"urls":["https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:66514","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-5704","https://bugzilla.redhat.com/show_bug.cgi?id=2455360","http://www.openwall.com/lists/oss-security/2026/04/11/10","http://www.openwall.com/lists/oss-security/2026/04/11/11","http://www.openwall.com/lists/oss-security/2026/04/12/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5704","description":"A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection."}]},{"artifact":{"id":"b958288bb0c2bb20","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.1.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.1.0","type":"npm","version":"10.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j6r3-76f7-8jcv","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j6r3-76f7-8jcv","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-07","epss":0.0037,"percentile":0.28818}],"risk":0.20904999999999999,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv","https://nvd.nist.gov/vuln/detail/CVE-2026-101912","https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j6r3-76f7-8jcv","description":"ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range"},"relatedVulnerabilities":[{"id":"CVE-2026-101912","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-07","epss":0.0037,"percentile":0.28818}],"urls":["https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101912","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"6c5c6b3dadd72c19","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/ip-address/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j6r3-76f7-8jcv","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-j6r3-76f7-8jcv","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-07","epss":0.0037,"percentile":0.28818}],"risk":0.20904999999999999,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv","https://nvd.nist.gov/vuln/detail/CVE-2026-101912","https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j6r3-76f7-8jcv","description":"ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range"},"relatedVulnerabilities":[{"id":"CVE-2026-101912","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101912","cwe":"CWE-697","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101912","cwe":"CWE-843","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101912","date":"2026-10-07","epss":0.0037,"percentile":0.28818}],"urls":["https://github.com/beaugunderson/ip-address/commit/1343629d57fea413644a5c9d41ff1e59619f3f28","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-j6r3-76f7-8jcv"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101912","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. A cross-family containment check whose leading address bits match makes the masked strings compare equal even though IPv4 and IPv6 do not share an address space. An allowlist or denylist decision can therefore classify an address outside the intended range as contained. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"b75bf6aa8d5be733","cpes":["cpe:2.3:a:cryptography.io:cryptography:48.0.0:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:48.0.0:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@48.0.0","type":"python","version":"48.0.0","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/METADATA","layerID":"sha256:88df3601988d6f0f90f6145bed05fd6f8badc8172b4d2c6eb12f91d30721378d","accessPath":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/RECORD","layerID":"sha256:88df3601988d6f0f90f6145bed05fd6f8badc8172b4d2c6eb12f91d30721378d","accessPath":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jwv3-5hgf-82ww","versionConstraint":">=42.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"48.0.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-jwv3-5hgf-82ww","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-07","epss":0.00252,"percentile":0.15288}],"risk":0.20412,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://nvd.nist.gov/vuln/detail/CVE-2026-69249","https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jwv3-5hgf-82ww","description":"python-cryptography: Duplicate self-signed intermediates can cause exponential path-building"},"relatedVulnerabilities":[{"id":"CVE-2026-69249","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69249","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69249","date":"2026-10-07","epss":0.00252,"percentile":0.15288}],"urls":["https://github.com/pyca/cryptography/commit/3763aa79b","https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582","https://github.com/pyca/cryptography/pull/14960","https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69249","description":"python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"risk":0.20110500000000003,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-07","epss":0.00369,"percentile":0.28625}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"213d133cc46bf69b","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3.1:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/debian/tar@1.35%2Bdfsg-3.1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.35+dfsg-3.1","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2005-2541","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"tar","version":"1.35+dfsg-3.1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2005-2541","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-07","epss":0.03992,"percentile":0.90243}],"risk":0.1996,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."},"relatedVulnerabilities":[{"id":"CVE-2005-2541","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","metrics":{"baseScore":10,"impactScore":10.1,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2005-2541","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2005-2541","date":"2026-10-07","epss":0.03992,"percentile":0.90243}],"urls":["http://marc.info/?l=bugtraq&m=112327628230258&w=2","https://lists.apache.org/thread.html/rc713534b10f9daeee2e0990239fa407e2118e4aa9e88a7041177497c%40%3Cissues.guacamole.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2005-2541","description":"Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-72897","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-72897","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"risk":0.1995,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected.  Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service.  CWE: CWE-787: Out-of-bounds Write  Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags.  An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process.  Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3.  The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity.  FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-72897","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-72897","cwe":"CWE-787","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-72897","date":"2026-10-07","epss":0.00266,"percentile":0.16931}],"urls":["https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922","https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e","https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61","https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-72897","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75806","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75806","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"risk":0.199305,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.  Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.  CWE: CWE-1284: Improper Validation of Specified Quantity in Input  Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.  In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.  The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75806","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75806","cwe":"CWE-1284","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75806","date":"2026-10-07","epss":0.00387,"percentile":0.30613}],"urls":["https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d","https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972","https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d","https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806","description":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.2"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-48142","versionConstraint":">= 1.0.0, < 1.30.3||>= 1.31.0, < 1.31.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.2"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-48142","versionConstraint":">= 1.0.0, < 1.30.3||>= 1.31.0, < 1.31.2 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-48142","fix":{"state":"fixed","versions":["1.30.3","1.31.2"],"available":[{"date":"2026-06-18","kind":"first-observed","version":"1.30.3"},{"date":"2026-06-18","kind":"first-observed","version":"1.31.2"}]},"cvss":[{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48142","cwe":"CWE-125","type":"Secondary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-48142","date":"2026-10-07","epss":0.00373,"percentile":0.29094}],"risk":0.19675749999999997,"urls":["https://my.f5.com/manage/s/article/K000161585"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48142","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42528","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42528","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-07","epss":0.00416,"percentile":0.33863}],"risk":0.19343999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.  Users are recommended to upgrade to version 2.4.69, which fixes this issue"},"relatedVulnerabilities":[{"id":"CVE-2026-42528","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42528","cwe":"CWE-789","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42528","date":"2026-10-07","epss":0.00416,"percentile":0.33863}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/12"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"risk":0.19197999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"risk":0.19197999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"risk":0.19197999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6791","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6791","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"risk":0.19197999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."},"relatedVulnerabilities":[{"id":"CVE-2026-6791","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6791","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-6791","date":"2026-10-07","epss":0.00331,"percentile":0.24167}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6791","description":"When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory.  The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-07","epss":0.00348,"percentile":0.26317}],"risk":0.18966000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-07","epss":0.00348,"percentile":0.26317}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1580","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1580","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-07","epss":0.03709,"percentile":0.89453}],"risk":0.18545,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1580","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1580","cwe":"CWE-189","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1580","date":"2026-10-07","epss":0.03709,"percentile":0.89453}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1580","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"b75bf6aa8d5be733","cpes":["cpe:2.3:a:cryptography.io:cryptography:48.0.0:*:*:*:*:python:*:*","cpe:2.3:a:cryptography.io:cryptography:48.0.0:*:*:*:*:*:*:*"],"name":"cryptography","purl":"pkg:pypi/cryptography@48.0.0","type":"python","version":"48.0.0","language":"python","licenses":["Apache-2.0 OR BSD-3-Clause"],"locations":[{"path":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/METADATA","layerID":"sha256:88df3601988d6f0f90f6145bed05fd6f8badc8172b4d2c6eb12f91d30721378d","accessPath":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/METADATA","annotations":{"evidence":"primary"}},{"path":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/RECORD","layerID":"sha256:88df3601988d6f0f90f6145bed05fd6f8badc8172b4d2c6eb12f91d30721378d","accessPath":"/opt/certbot/lib/python3.13/site-packages/cryptography-48.0.0.dist-info/RECORD","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"49.0.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m2h6-j472-rp4c","versionConstraint":">=45.0.0,<49.0.0 (python)"},"matcher":"python-matcher","searchedBy":{"package":{"name":"cryptography","version":"48.0.0"},"language":"python","namespace":"github:language:python"}}],"vulnerability":{"id":"GHSA-m2h6-j472-rp4c","fix":{"state":"fixed","versions":["49.0.0"],"available":[{"date":"2026-08-04","kind":"first-observed","version":"49.0.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69248","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69248","date":"2026-10-07","epss":0.00309,"percentile":0.21731}],"risk":0.183855,"urls":["https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://nvd.nist.gov/vuln/detail/CVE-2026-69248","https://github.com/pyca/cryptography/commit/286c89128","https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3554.yaml"],"severity":"Medium","namespace":"github:language:python","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m2h6-j472-rp4c","description":"python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees"},"relatedVulnerabilities":[{"id":"CVE-2026-69248","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-69248","cwe":"CWE-295","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-69248","date":"2026-10-07","epss":0.00309,"percentile":0.21731}],"urls":["https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2","https://github.com/pyca/cryptography/pull/14888","https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-69248","description":"cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75804","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75804","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"risk":0.18128,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits.  Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size).  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data.  Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error.  The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met:   - the remote peer opens several streams   - each stream must stay within the stream-level flow control limit   - there must be no zero-offset byte sent on any of the streams     (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75804","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75804","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75804","date":"2026-10-07","epss":0.00352,"percentile":0.26736}],"urls":["https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e","https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538","https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a","https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75804","description":"Issue summary: OpenSSL QUIC stack does not enforce connection\nlevel flow control for streams. Remote peers may send more bytes\nas long as they fit within the stream flow control limits.\n\nImpact summary: A malicious remote peer may exploit the lack of connection\nflow control for streams to make the QUIC stack receive ~100MB of memory\ninstead of 768 KiB (default flow control window size).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The local QUIC stack advertises two flow control limits\nto its remote peer: stream flow control limit and connection flow\ncontrol limit. The remote peer must follow both limits when transmitting\nstream data.\n\nWhenever the local QUIC stack receives a stream frame, it validates\nthat the size of the received stream frame stays within flow control limits.\nIf either limit is exceeded (stream level or connection level), then\nthe QUIC stack must close the connection with a flow control error.\n\nThe vulnerable OpenSSL QUIC stack enforces the stream-level but not\nthe connection-level limit. To exploit the issue, three conditions must be met:\n  - the remote peer opens several streams\n  - each stream must stay within the stream-level flow control limit\n  - there must be no zero-offset byte sent on any of the streams\n    (to prevent the vulnerable QUIC stack from consuming data).\nBy meeting the conditions above, the remote peer may make the local stack\nallocate 2 x MAX_STREAMS x (stream flow control limit) bytes\nof memory. MAX_STREAMS defaults to 100, and the limit applies to both\nbidirectional and unidirectional streams, making it 200 in total. The default\nflow control window for a stream is 512kB. The remote peer may\nforce the vulnerable QUIC stack to allocate 100MB of heap per connection.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"f192cb8dc63f3eb4","cpes":["cpe:2.3:a:cpp-14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14","purl":"pkg:deb/debian/cpp-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/cpp-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"1580254f2d5cda2a","cpes":["cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux-gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux_gnu:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64-linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64_linux:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86-64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86_64:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14-x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14_x86:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp-14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp_14:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:cpp:cpp_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"cpp-14-x86-64-linux-gnu","purl":"pkg:deb/debian/cpp-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/cpp-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/cpp-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"bf427850ceb9b9cf","cpes":["cpe:2.3:a:g\\+\\+-14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14","purl":"pkg:deb/debian/g%2B%2B-14@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/g++-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"64cb91ba3690d600","cpes":["cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux-gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux_gnu:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64-linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64_linux:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86-64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86_64:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14-x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14_x86:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+-14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+_14:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:g\\+\\+:g\\+\\+_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"g++-14-x86-64-linux-gnu","purl":"pkg:deb/debian/g%2B%2B-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/g++-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/g++-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"1753e0ab4835d319","cpes":["cpe:2.3:a:gcc-14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14","purl":"pkg:deb/debian/gcc-14@14.2.0-19?arch=amd64&distro=debian-13.7","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/gcc-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"8a928cc6733b8d4c","cpes":["cpe:2.3:a:gcc-14-base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_base:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-base:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_base:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-base","purl":"pkg:deb/debian/gcc-14-base@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/gcc-14-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/gcc-14-base:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"afc74f4635aa2de5","cpes":["cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux-gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux_gnu:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64-linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64_linux:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86-64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86_64:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14-x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14_x86:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc-14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc_14:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc-14-x86-64-linux-gnu:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:gcc:gcc_14_x86_64_linux_gnu:14.2.0-19:*:*:*:*:*:*:*"],"name":"gcc-14-x86-64-linux-gnu","purl":"pkg:deb/debian/gcc-14-x86-64-linux-gnu@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/gcc-14-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/gcc-14-x86-64-linux-gnu.list"}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"7475a27907fe4420","cpes":["cpe:2.3:a:libasan8:libasan8:14.2.0-19:*:*:*:*:*:*:*"],"name":"libasan8","purl":"pkg:deb/debian/libasan8@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libasan8/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libasan8:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libasan8:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"4aef59838e786012","cpes":["cpe:2.3:a:libatomic1:libatomic1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libatomic1","purl":"pkg:deb/debian/libatomic1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libatomic1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libatomic1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"062249237978e3de","cpes":["cpe:2.3:a:libcc1-0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1-0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1_0:libcc1_0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1-0:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libcc1:libcc1_0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libcc1-0","purl":"pkg:deb/debian/libcc1-0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libcc1-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libcc1-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"ef5dd5e55126a732","cpes":["cpe:2.3:a:libgcc-14-dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14-dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14_dev:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_14:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-14-dev","purl":"pkg:deb/debian/libgcc-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libgcc-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libgcc-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"2338ed612a82adf3","cpes":["cpe:2.3:a:libgcc-s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc-s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc_s1:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc-s1:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libgcc:libgcc_s1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgcc-s1","purl":"pkg:deb/debian/libgcc-s1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libgcc-s1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libgcc-s1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"71d32d5417d636ce","cpes":["cpe:2.3:a:libgomp1:libgomp1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libgomp1","purl":"pkg:deb/debian/libgomp1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libgomp1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libgomp1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"81d0f863177c4ff2","cpes":["cpe:2.3:a:libhwasan0:libhwasan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libhwasan0","purl":"pkg:deb/debian/libhwasan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libhwasan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libhwasan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"30ada6cb82fd6f02","cpes":["cpe:2.3:a:libitm1:libitm1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libitm1","purl":"pkg:deb/debian/libitm1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libitm1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libitm1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libitm1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"d3f0e91aac2169e5","cpes":["cpe:2.3:a:liblsan0:liblsan0:14.2.0-19:*:*:*:*:*:*:*"],"name":"liblsan0","purl":"pkg:deb/debian/liblsan0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblsan0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/liblsan0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"2e7766dcd5ecb5f3","cpes":["cpe:2.3:a:libquadmath0:libquadmath0:14.2.0-19:*:*:*:*:*:*:*"],"name":"libquadmath0","purl":"pkg:deb/debian/libquadmath0@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libquadmath0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libquadmath0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"0f0a43dbd793abf5","cpes":["cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14-dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14_dev:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+-14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+_14:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+-14-dev:14.2.0-19:*:*:*:*:*:*:*","cpe:2.3:a:libstdc\\+\\+:libstdc\\+\\+_14_dev:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++-14-dev","purl":"pkg:deb/debian/libstdc%2B%2B-14-dev@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libstdc++-14-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libstdc++-14-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"7dc961cf921ecd08","cpes":["cpe:2.3:a:libstdc\\+\\+6:libstdc\\+\\+6:14.2.0-19:*:*:*:*:*:*:*"],"name":"libstdc++6","purl":"pkg:deb/debian/libstdc%2B%2B6@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libstdc++6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libstdc++6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"3faa4e2eb1e6610c","cpes":["cpe:2.3:a:libtsan2:libtsan2:14.2.0-19:*:*:*:*:*:*:*"],"name":"libtsan2","purl":"pkg:deb/debian/libtsan2@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libtsan2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libtsan2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"79fd96516c7017fa","cpes":["cpe:2.3:a:libubsan1:libubsan1:14.2.0-19:*:*:*:*:*:*:*"],"name":"libubsan1","purl":"pkg:deb/debian/libubsan1@14.2.0-19?arch=amd64&distro=debian-13.7&upstream=gcc-14","type":"deb","version":"14.2.0-19","language":"","licenses":["sha256:20390f8a6f3b1e4d7cb45dd8652dabb259bbef688cbad839bcdb0b9ba7252f79"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gcc-14-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libubsan1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libubsan1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"gcc-14"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102010","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"gcc-14","version":"14.2.0-19"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-102010","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"risk":0.18125,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."},"relatedVulnerabilities":[{"id":"CVE-2026-102010","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","metrics":{"baseScore":7,"impactScore":4.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102010","cwe":"CWE-825","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102010","date":"2026-10-07","epss":0.0025,"percentile":0.14922}],"urls":["https://access.redhat.com/errata/RHSA-2026:73642","https://access.redhat.com/errata/RHSA-2026:74569","https://access.redhat.com/security/cve/CVE-2026-102010","https://bugzilla.redhat.com/show_bug.cgi?id=2478395"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption."}]},{"artifact":{"id":"de3bcbf9daefbcfb","cpes":["cpe:2.3:a:libnghttp2-14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2-14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2_14:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2-14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libnghttp2:libnghttp2_14:1.64.0-1.1\\+deb13u1:*:*:*:*:*:*:*"],"name":"libnghttp2-14","purl":"pkg:deb/debian/libnghttp2-14@1.64.0-1.1%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=nghttp2","type":"deb","version":"1.64.0-1.1+deb13u1","language":"","licenses":["BSD-2-clause","Expat","GPL-3","GPL-3+","MIT","all-permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libnghttp2-14/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libnghttp2-14/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libnghttp2-14:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"nghttp2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-58055","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"nghttp2","version":"1.64.0-1.1+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-07","epss":0.00319,"percentile":0.22798}],"risk":0.18023499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-58055","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-07","epss":0.00319,"percentile":0.22798}],"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."}]},{"artifact":{"id":"310cafbbd5abd891","cpes":["cpe:2.3:a:postcss-selector-parser:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector-parser:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector_parser:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss-selector:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss_selector:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss-selector-parser:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:postcss:postcss_selector_parser:7.1.1:*:*:*:*:*:*:*"],"name":"postcss-selector-parser","purl":"pkg:npm/postcss-selector-parser@7.1.1","type":"npm","version":"7.1.1","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.1.3"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w9m9-85wc-3x92","versionConstraint":">=7.1.0,<7.1.3 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"postcss-selector-parser","version":"7.1.1"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-w9m9-85wc-3x92","fix":{"state":"fixed","versions":["7.1.3"],"available":[{"date":"2026-09-01","kind":"first-observed","version":"7.1.3"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9358","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-9358","cwe":"CWE-674","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-9358","date":"2026-10-07","epss":0.0058,"percentile":0.45968}],"risk":0.1798,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-9358","https://gist.github.com/bx33661/581e3a38134601c04e19b4dfc9b459b9","https://vuldb.com/submit/813080","https://vuldb.com/vuln/365321","https://vuldb.com/vuln/365321/cti","https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d","https://github.com/postcss/postcss-selector-parser/commit/e37c5b0b785b165e27508d2489fdec8e0f18b10a","https://github.com/postcss/postcss-selector-parser/releases/tag/6.1.3","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.3","https://vuldb.com/cve/CVE-2026-9358"],"severity":"Low","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w9m9-85wc-3x92","description":"postcss-selector-parser allows denial of service through uncontrolled AST recursion"},"relatedVulnerabilities":[{"id":"CVE-2026-9358","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9358","cwe":"CWE-404","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2026-9358","cwe":"CWE-674","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2026-9358","date":"2026-10-07","epss":0.0058,"percentile":0.45968}],"urls":["https://gist.github.com/bx33661/581e3a38134601c04e19b4dfc9b459b9","https://github.com/postcss/postcss-selector-parser/commit/5bc698cef66f8abd12610dc623e5d67cbc0f869d","https://github.com/postcss/postcss-selector-parser/releases/tag/7.1.3","https://vuldb.com/cve/CVE-2026-9358","https://vuldb.com/submit/813080","https://vuldb.com/vuln/365321","https://vuldb.com/vuln/365321/cti"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9358","description":"A vulnerability was determined in postcss-selector-parser up to 6.1.2/7.1.2. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 6.1.3 and 7.1.3 is able to address this issue. This patch is called 5bc698cef66f8abd12610dc623e5d67cbc0f869d. It is suggested to upgrade the affected component. The vendor explains, that according to his definition \"DoS on server-side on user-generated CSS is low risk for us (since most users compile own CSS with PostCSS).\" The commits were backported to 6.x branch, which was the most downloaded version."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-15919","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-15919","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15919","date":"2026-10-07","epss":0.03557,"percentile":0.88998}],"risk":0.17784999999999998,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-15919","description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'"},"relatedVulnerabilities":[{"id":"CVE-2018-15919","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2018-15919","cwe":"CWE-200","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2018-15919","date":"2026-10-07","epss":0.03557,"percentile":0.88998}],"urls":["http://seclists.org/oss-sec/2018/q3/180","http://www.securityfocus.com/bid/105163","https://security.netapp.com/advisory/ntap-20181221-0001/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-15919","description":"Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or \"oracle\") as a vulnerability.'"}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"risk":0.17612999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.  The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-07","epss":0.00342,"percentile":0.25583}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"risk":0.1728,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-07","epss":0.00216,"percentile":0.10985}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"b958288bb0c2bb20","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.1.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.1.0","type":"npm","version":"10.1.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3mg-xc3c-68pw","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-h3mg-xc3c-68pw","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-07","epss":0.00301,"percentile":0.20939}],"risk":0.170065,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw","https://nvd.nist.gov/vuln/detail/CVE-2026-101911","https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3mg-xc3c-68pw","description":"ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process"},"relatedVulnerabilities":[{"id":"CVE-2026-101911","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-07","epss":0.00301,"percentile":0.20939}],"urls":["https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101911","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"6c5c6b3dadd72c19","cpes":["cpe:2.3:a:beaugunderson:ip-address:10.5.0:*:*:*:*:node.js:*:*"],"name":"ip-address","purl":"pkg:npm/ip-address@10.5.0","type":"npm","version":"10.5.0","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/ip-address/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/ip-address/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"10.7.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-h3mg-xc3c-68pw","versionConstraint":"<=10.7.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"ip-address","version":"10.5.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-h3mg-xc3c-68pw","fix":{"state":"fixed","versions":["10.7.1"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"10.7.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-07","epss":0.00301,"percentile":0.20939}],"risk":0.170065,"urls":["https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw","https://nvd.nist.gov/vuln/detail/CVE-2026-101911","https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-h3mg-xc3c-68pw","description":"ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process"},"relatedVulnerabilities":[{"id":"CVE-2026-101911","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-101911","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-101911","cwe":"CWE-770","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-101911","date":"2026-10-07","epss":0.00301,"percentile":0.20939}],"urls":["https://github.com/beaugunderson/ip-address/commit/469ead1231b4cc059f2150c626e1e0c2895c0134","https://github.com/beaugunderson/ip-address/commit/8b34a21e0839b37c094066816fb2c2c48a2adcf5","https://github.com/beaugunderson/ip-address/releases/tag/v10.7.1","https://github.com/beaugunderson/ip-address/security/advisories/GHSA-h3mg-xc3c-68pw"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-101911","description":"ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in src/ipv6.ts accept unbounded strings and expand invalid characters through RE_BAD_CHARACTERS into large diagnostics. Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 parsing without an earlier length bound. Common URL and header limits, and common body-parser defaults, generally constrain the effect; common defaults typically exclude 32 MiB fields. Megabyte-scale fields can cause a synchronous stall and high transient memory use, approximately 16 MiB can trigger an invalid string length exception, and process termination occurs at approximately 32 MiB. The affected entry points include Address6.isValid and construction paths that reach parse. This issue is fixed in version 10.7.1."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42772","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42772","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"risk":0.16995000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.  Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.  CWE: CWE-407: Inefficient Algorithmic Complexity  Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`.  By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.  FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-42772","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42772","cwe":"CWE-407","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-42772","date":"2026-10-07","epss":0.0033,"percentile":0.24007}],"urls":["https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","description":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary."}]},{"artifact":{"id":"6c23b5fbc804d426","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/debian/python3-pip-whl@25.1.1%2Bdfsg-1?arch=all&distro=debian-13.7&upstream=python-pip","type":"deb","version":"25.1.1+dfsg-1","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13346","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python-pip","version":"25.1.1+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13346","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-07","epss":0.00292,"percentile":0.19965}],"risk":0.16789999999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13346","description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.     This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time."},"relatedVulnerabilities":[{"id":"CVE-2026-13346","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13346","cwe":"CWE-36","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-13346","date":"2026-10-07","epss":0.00292,"percentile":0.19965}],"urls":["https://github.com/pypa/pip/pull/14110","https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/","http://www.openwall.com/lists/oss-security/2026/07/29/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13346","description":"pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.\n\n\n\n\nThis vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-60001","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-60001","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-07","epss":0.00291,"percentile":0.1981}],"risk":0.16732499999999997,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."},"relatedVulnerabilities":[{"id":"CVE-2026-60001","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-60001","cwe":"CWE-770","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-60001","date":"2026-10-07","epss":0.00291,"percentile":0.1981}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-60001","description":"sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"risk":0.166155,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"risk":0.166155,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"risk":0.166155,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"risk":0.166155,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"risk":0.166155,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-07","epss":0.00209,"percentile":0.10193}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010022","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010022","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"risk":0.16245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010022","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","metrics":{"baseScore":7.5,"impactScore":6.5,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010022","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010022","date":"2026-10-07","epss":0.03249,"percentile":0.87951}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010022","https://sourceware.org/bugzilla/show_bug.cgi?id=22850","https://sourceware.org/bugzilla/show_bug.cgi?id=22850#c3","https://ubuntu.com/security/CVE-2019-1010022"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010022","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"cb5be0a6f4d630dc","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.46-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.46-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/debian/libpcre2-8-0@10.46-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=pcre2","type":"deb","version":"10.46-1~deb13u2","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"fix":{"suggestedVersion":"10.46-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"< 10.46-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"pcre2","version":"10.46-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"fixed","versions":["10.46-1~deb13u3"],"available":[{"date":"2026-09-29","kind":"advisory","version":"10.46-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-07","epss":0.00214,"percentile":0.10801}],"risk":0.16157000000000002,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6530-1","link":"https://security-tracker.debian.org/tracker/DSA-6530-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-07","epss":0.00214,"percentile":0.10801}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010024","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010024","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"risk":0.15965000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010024","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010024","cwe":"CWE-200","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010024","date":"2026-10-07","epss":0.03193,"percentile":0.87721}],"urls":["http://www.securityfocus.com/bid/109162","https://security-tracker.debian.org/tracker/CVE-2019-1010024","https://sourceware.org/bugzilla/show_bug.cgi?id=22852","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010024"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010024","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42356","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42356","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-07","epss":0.0047,"percentile":0.38636}],"risk":0.15745,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.    This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."},"relatedVulnerabilities":[{"id":"CVE-2026-42356","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42356","cwe":"CWE-430","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2026-42356","date":"2026-10-07","epss":0.0047,"percentile":0.38636}],"urls":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/11"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42356","description":"Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.60 through 2.4.68."}]},{"artifact":{"id":"96caf0301a242106","cpes":["cpe:2.3:a:juliangruber:brace-expansion:2.0.2:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@2.0.2","type":"npm","version":"2.0.2","language":"javascript","licenses":["MIT"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"2.1.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=2.0.0,<2.1.7 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"2.0.2"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["2.1.7"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.1.7"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-07","epss":0.00301,"percentile":0.2094}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-07","epss":0.00301,"percentile":0.2094}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"04e02497b9a7e6b4","cpes":["cpe:2.3:a:juliangruber:brace-expansion:5.0.9:*:*:*:*:node.js:*:*"],"name":"brace-expansion","purl":"pkg:npm/brace-expansion@5.0.9","type":"npm","version":"5.0.9","language":"javascript","licenses":["MIT"],"locations":[{"path":"/app/node_modules/brace-expansion/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/brace-expansion/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"5.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q2hr-2g5m-vwhr","versionConstraint":">=4.0.0,<5.0.12 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"brace-expansion","version":"5.0.9"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-q2hr-2g5m-vwhr","fix":{"state":"fixed","versions":["5.0.12"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"5.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-07","epss":0.00301,"percentile":0.2094}],"risk":0.15501500000000001,"urls":["https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr","https://nvd.nist.gov/vuln/detail/CVE-2026-102277","https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q2hr-2g5m-vwhr","description":"brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service"},"relatedVulnerabilities":[{"id":"CVE-2026-102277","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102277","cwe":"CWE-400","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-102277","cwe":"CWE-407","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-102277","date":"2026-10-07","epss":0.00301,"percentile":0.2094}],"urls":["https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96","https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22","https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364","https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e","https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102277","description":"The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The successive full-input rescans with linear working-string growth cause quadratic CPU time and memory pressure that can block the Node.js event loop. The process eventually recovers, making the impact a recoverable CPU denial of service. This issue is fixed in versions 1.1.21, 2.1.7, 3.0.9, and 5.0.12."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1581","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1581","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-07","epss":0.0308,"percentile":0.87284}],"risk":0.15400000000000003,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."},"relatedVulnerabilities":[{"id":"CVE-2003-1581","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.6,"impactScore":2.9,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1581","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1581","date":"2026-10-07","epss":0.0308,"percentile":0.87284}],"urls":["http://www.securityfocus.com/archive/1/313867"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1581","description":"The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an \"Inverse Lookup Log Corruption (ILLC)\" issue."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010023","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010023","fix":{"state":"not-fixed","versions":[]},"cvss":[],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"risk":0.1522,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."},"relatedVulnerabilities":[{"id":"CVE-2019-1010023","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","metrics":{"baseScore":6.8,"impactScore":6.5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2019-1010023","date":"2026-10-07","epss":0.03044,"percentile":0.87131}],"urls":["http://www.securityfocus.com/bid/109167","https://security-tracker.debian.org/tracker/CVE-2019-1010023","https://sourceware.org/bugzilla/show_bug.cgi?id=22851","https://support.f5.com/csp/article/K11932200?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010023"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010023","description":"GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this is being treated as a non-security bug and no real threat."}]},{"artifact":{"id":"ff4a1d6eaa066fa1","cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*","cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"name":"nginx","purl":"pkg:generic/nginx@1.31.1","type":"binary","version":"1.31.1","language":"","licenses":[],"locations":[{"path":"/usr/sbin/nginx","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/usr/sbin/nginx","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"1.31.6"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-90439","versionConstraint":">= 1.29.2, < 1.30.0||>= 1.30.4, < 1.30.5||>= 1.31.0, < 1.31.6 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:f5:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}},{"fix":{"suggestedVersion":"1.31.6"},"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nginx:nginx:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-90439","versionConstraint":">= 1.29.2, < 1.30.0||>= 1.30.4, < 1.30.5||>= 1.31.0, < 1.31.6 (unknown)"},"matcher":"stock-matcher","searchedBy":{"cpes":["cpe:2.3:a:nginx:nginx:1.31.1:*:*:*:*:*:*:*"],"package":{"name":"nginx","version":"1.31.1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-90439","fix":{"state":"fixed","versions":["1.30.0","1.30.5","1.31.6"],"available":[{"date":"2026-09-26","kind":"first-observed","version":"1.30.0"},{"date":"2026-09-25","kind":"first-observed","version":"1.30.5"},{"date":"2026-09-25","kind":"first-observed","version":"1.31.6"}]},"cvss":[{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"f5sirt@f5.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90439","cwe":"CWE-122","type":"Secondary","source":"f5sirt@f5.com"}],"epss":[{"cve":"CVE-2026-90439","date":"2026-10-07","epss":0.00256,"percentile":0.15852}],"risk":0.14976,"urls":["https://my.f5.com/manage/s/article/K000162604"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90439","description":"NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This may cause a heap buffer overflow in the NGINX worker process leading to a restart and/or limited data corruption.\n\nImpact:\nThis vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or limited data corruption. There is no control plane exposure; this is a data plane issue only.\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."},"relatedVulnerabilities":[]},{"artifact":{"id":"ea4018933b7b4ef6","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/debian/libx11-6@2%3A1.8.12-1?arch=amd64&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-07","epss":0.00199,"percentile":0.08912}],"risk":0.14925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-07","epss":0.00199,"percentile":0.08912}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"25c33176f8e0362a","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/debian/libx11-data@2%3A1.8.12-1?arch=all&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-88806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-88806","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-07","epss":0.00199,"percentile":0.08912}],"risk":0.14925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."},"relatedVulnerabilities":[{"id":"CVE-2026-88806","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.5,"impactScore":5.9,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-88806","cwe":"CWE-122","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-88806","date":"2026-10-07","epss":0.00199,"percentile":0.08912}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-88806","description":"A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"risk":0.14322000000000001,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-07","epss":0.00186,"percentile":0.07543}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"0eeeff6f9a118e0b","cpes":["cpe:2.3:a:sigstore:sigstore:3.1.0:*:*:*:*:node.js:*:*"],"name":"sigstore","purl":"pkg:npm/sigstore@3.1.0","type":"npm","version":"3.1.0","language":"javascript","licenses":["Apache-2.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/sigstore/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/sigstore/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"4.1.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-52v5-jr5w-gjxr","versionConstraint":"<=4.1.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"sigstore","version":"3.1.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-52v5-jr5w-gjxr","fix":{"state":"fixed","versions":["4.1.1"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"4.1.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48815","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48815","date":"2026-10-07","epss":0.0019,"percentile":0.0789}],"risk":0.14250000000000002,"urls":["https://github.com/sigstore/sigstore-js/security/advisories/GHSA-52v5-jr5w-gjxr"],"severity":"High","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-52v5-jr5w-gjxr","description":"sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced"},"relatedVulnerabilities":[{"id":"CVE-2026-48815","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48815","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48815","date":"2026-10-07","epss":0.0019,"percentile":0.0789}],"urls":["https://github.com/sigstore/sigstore-js/commit/7845532f9d17f6f765363dbee82b01bd159fb52b","https://github.com/sigstore/sigstore-js/pull/1658","https://github.com/sigstore/sigstore-js/releases/tag/sigstore%404.1.1","https://github.com/sigstore/sigstore-js/security/advisories/GHSA-52v5-jr5w-gjxr"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48815","description":"sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certificateOIDs option in sigstore.verify() is accepted by the public API but discarded before verification, so required certificate extension OIDs are never checked and applications relying on certificateOIDs to restrict which certificates may sign artifacts can accept unauthorized certificates. This issue is fixed in version 4.1.1."}]},{"artifact":{"id":"893ab677af71bedc","cpes":["cpe:2.3:a:login.defs:login.defs:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"login.defs","purl":"pkg:deb/debian/login.defs@1%3A4.17.4-2?arch=all&distro=debian-13.7&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login.defs/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/login.defs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.postinst"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-07","epss":0.00426,"percentile":0.34871}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-07","epss":0.00426,"percentile":0.34871}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"a0c2eaa9ca5431ff","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.17.4-2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/debian/passwd@1%3A4.17.4-2?arch=amd64&distro=debian-13.7&upstream=shadow","type":"deb","version":"1:4.17.4-2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"shadow","version":"1:4.17.4-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-07","epss":0.00426,"percentile":0.34871}],"risk":0.14057999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-07","epss":0.00426,"percentile":0.34871}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35189","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35189","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"risk":0.13750500000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.  Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.  CWE: CWE-770: Allocation of Resources Without Limits or Throttling  Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake.  This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.  The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.  FIPS impact: no The affected code is outside the FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-35189","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35189","cwe":"CWE-770","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35189","date":"2026-10-07","epss":0.00267,"percentile":0.17263}],"urls":["https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84","https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89","https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f","https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35189","description":"Issue summary: A certificate with many nameRelativeToCRLIssuer CRL\ndistribution points causes disproportionate heap growth when OpenSSL caches\nX.509 extensions.\n\nImpact summary: Receiving a crafted certificate from a malicious peer can lead\nto significant memory pressure and possible Denial of Service in clients or\nin servers that solicit client certificates.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: A certificate or a set of certificates that fits under the limit for\nsize of certificates accepted from the peer (~100 KiB) can result in allocation\nof several hundred MiB of resident memory on the receiving side\nduring a normal TLS handshake.  This may be enough to crash the client or\nserver, if multiple concurrent connections lead to similarly large memory\nallocations.\n\nThe fix postpones processing of the CRL distribution points extensions in\ncertificates to the time when the processed value is required for CRL processing.\nThis avoids keeping large memory allocations for a long time when such\ncertificates are received.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}]},{"artifact":{"id":"109a3f7b27f2059b","cpes":["cpe:2.3:a:\\@sigstore\\/core:\\@sigstore\\/core:2.0.0:*:*:*:*:*:*:*","cpe:2.3:a:sigstore:\\@sigstore\\/core:2.0.0:*:*:*:*:*:*:*"],"name":"@sigstore/core","purl":"pkg:npm/%40sigstore/core@2.0.0","type":"npm","version":"2.0.0","language":"javascript","licenses":["Apache-2.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/@sigstore/core/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/@sigstore/core/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.2.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jfc7-64v2-mr8c","versionConstraint":"<=3.2.0 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"@sigstore/core","version":"2.0.0"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-jfc7-64v2-mr8c","fix":{"state":"fixed","versions":["3.2.1"],"available":[{"date":"2026-06-27","kind":"first-observed","version":"3.2.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48758","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48758","date":"2026-10-07","epss":0.00264,"percentile":0.16809}],"risk":0.13727999999999999,"urls":["https://github.com/sigstore/sigstore-js/security/advisories/GHSA-jfc7-64v2-mr8c"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jfc7-64v2-mr8c","description":"@sigstore/core has DSSE payloadType type-binding failure"},"relatedVulnerabilities":[{"id":"CVE-2026-48758","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48758","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-48758","date":"2026-10-07","epss":0.00264,"percentile":0.16809}],"urls":["https://github.com/sigstore/sigstore-js/commit/b5aa4f1f8d2db0a9dfa6430fb114d9c2f1c304f7","https://github.com/sigstore/sigstore-js/pull/1657","https://github.com/sigstore/sigstore-js/releases/tag/%40sigstore%2Fcore%403.2.1","https://github.com/sigstore/sigstore-js/security/advisories/GHSA-jfc7-64v2-mr8c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48758","description":"sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.2.1, the preAuthEncoding function in @sigstore/core uses Node.js ascii encoding when converting the PAE string to bytes, allowing payloadType to be mutated after signing without invalidating the signature and breaking the type-binding guarantee that DSSE is designed to provide. This issue is fixed in version 3.2.1."}]},{"artifact":{"id":"e9d28bf4fecb65b4","cpes":["cpe:2.3:a:libperl5.40:libperl5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"libperl5.40","purl":"pkg:deb/debian/libperl5.40@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libperl5.40/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libperl5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libperl5.40:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"8d18bdf2d28de8c0","cpes":["cpe:2.3:a:perl:perl:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl","purl":"pkg:deb/debian/perl@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/perl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.list"},{"path":"/var/lib/dpkg/info/perl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl.postinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"1ed310f43f3fc66d","cpes":["cpe:2.3:a:perl-base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/debian/perl-base@5.40.1-6%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-base.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"ec18de78d97e6b78","cpes":["cpe:2.3:a:perl-modules-5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules-5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules_5.40:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl-modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl_modules:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-modules-5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_modules_5.40:5.40.1-6\\+deb13u1:*:*:*:*:*:*:*"],"name":"perl-modules-5.40","purl":"pkg:deb/debian/perl-modules-5.40@5.40.1-6%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=perl","type":"deb","version":"5.40.1-6+deb13u1","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-modules-5.40/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/perl-modules-5.40/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-modules-5.40.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/perl-modules-5.40.list"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15534","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"perl","version":"5.40.1-6+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15534","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"risk":0.13696,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.  The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.  A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."},"relatedVulnerabilities":[{"id":"CVE-2026-15534","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15534","cwe":"CWE-125","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-190","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"cve":"CVE-2026-15534","cwe":"CWE-787","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-15534","date":"2026-10-07","epss":0.00256,"percentile":0.15819}],"urls":["https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb.patch","https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0.patch","http://www.openwall.com/lists/oss-security/2026/08/09/12","http://www.openwall.com/lists/oss-security/2026/08/09/13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15534","description":"Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.\n\nThe regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.\n\nA caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory."}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"risk":0.135915,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"risk":0.135915,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"risk":0.135915,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"risk":0.135915,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"risk":0.135915,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard   compressions, Python could use an attacker-controlled size to   pre-allocate memory, possibly resulting in memory exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-07","epss":0.00533,"percentile":0.43218}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106552","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106552","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-07","epss":0.00291,"percentile":0.19794}],"risk":0.13385999999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."},"relatedVulnerabilities":[{"id":"CVE-2026-106552","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106552","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106552","date":"2026-10-07","epss":0.00291,"percentile":0.19794}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106552","description":"In sftp in OpenSSH before 10.6, a server can trigger directory traversal (causing files to be written to unintended locations) during a recursive copy operation."}]},{"artifact":{"id":"7a21ed9bbad10f4c","cpes":["cpe:2.3:a:binutils:binutils:2.44-3:*:*:*:*:*:*:*"],"name":"binutils","purl":"pkg:deb/debian/binutils@2.44-3?arch=amd64&distro=debian-13.7","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/binutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils.list"},{"path":"/var/lib/dpkg/info/binutils.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils.preinst"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"09e57864f3ee2d85","cpes":["cpe:2.3:a:binutils-common:binutils-common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-common:binutils_common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils-common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_common:binutils_common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-common:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_common:2.44-3:*:*:*:*:*:*:*"],"name":"binutils-common","purl":"pkg:deb/debian/binutils-common@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/binutils-common/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils-common:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"b048185e7cf16adc","cpes":["cpe:2.3:a:binutils-x86-64-linux-gnu:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux-gnu:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux_gnu:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64-linux:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64_linux:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86-64:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86_64:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils-x86:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils_x86:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils-x86-64-linux-gnu:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:binutils:binutils_x86_64_linux_gnu:2.44-3:*:*:*:*:*:*:*"],"name":"binutils-x86-64-linux-gnu","purl":"pkg:deb/debian/binutils-x86-64-linux-gnu@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/binutils-x86-64-linux-gnu/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/binutils-x86-64-linux-gnu.list"}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"36f20bcb4ff2650f","cpes":["cpe:2.3:a:libbinutils:libbinutils:2.44-3:*:*:*:*:*:*:*"],"name":"libbinutils","purl":"pkg:deb/debian/libbinutils@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libbinutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libbinutils:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"b0a949b30d35d392","cpes":["cpe:2.3:a:libctf-nobfd0:libctf-nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf-nobfd0:libctf_nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf-nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf_nobfd0:libctf_nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf-nobfd0:2.44-3:*:*:*:*:*:*:*","cpe:2.3:a:libctf:libctf_nobfd0:2.44-3:*:*:*:*:*:*:*"],"name":"libctf-nobfd0","purl":"pkg:deb/debian/libctf-nobfd0@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libctf-nobfd0/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libctf-nobfd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libctf-nobfd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"820e67ebcb63a2a2","cpes":["cpe:2.3:a:libctf0:libctf0:2.44-3:*:*:*:*:*:*:*"],"name":"libctf0","purl":"pkg:deb/debian/libctf0@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libctf0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libctf0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libctf0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"77edfb107040a28c","cpes":["cpe:2.3:a:libgprofng0:libgprofng0:2.44-3:*:*:*:*:*:*:*"],"name":"libgprofng0","purl":"pkg:deb/debian/libgprofng0@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/binutils-common/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libgprofng0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libgprofng0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"9c03630d3a75e45e","cpes":["cpe:2.3:a:libsframe1:libsframe1:2.44-3:*:*:*:*:*:*:*"],"name":"libsframe1","purl":"pkg:deb/debian/libsframe1@2.44-3?arch=amd64&distro=debian-13.7&upstream=binutils","type":"deb","version":"2.44-3","language":"","licenses":["sha256:20a9818b14f941467bcc0f459a1b1951e3bfecc1cc259e5004f8b9a80d7dc804"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsframe1/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libsframe1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libsframe1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"binutils"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-20712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"binutils","version":"2.44-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-20712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"risk":0.13375,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."},"relatedVulnerabilities":[{"id":"CVE-2018-20712","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-20712","cwe":"CWE-125","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-20712","date":"2026-10-07","epss":0.02675,"percentile":0.85345}],"urls":["http://www.securityfocus.com/bid/106563","https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88629","https://sourceware.org/bugzilla/show_bug.cgi?id=24043","https://support.f5.com/csp/article/K38336243"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-20712","description":"A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2010-4756","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2010-4756","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"risk":0.13165,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."},"relatedVulnerabilities":[{"id":"CVE-2010-4756","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":4,"impactScore":2.9,"exploitabilityScore":8},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2010-4756","cwe":"CWE-399","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2010-4756","date":"2026-10-07","epss":0.02633,"percentile":0.85083}],"urls":["http://cxib.net/stuff/glob-0day.c","http://securityreason.com/achievement_securityalert/89","http://securityreason.com/exploitalert/9223","https://bugzilla.redhat.com/show_bug.cgi?id=681681","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-4756","https://security.netapp.com/advisory/ntap-20241108-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2010-4756","description":"The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632."}]},{"artifact":{"id":"8e03bdf0d5ec8f50","cpes":["cpe:2.3:a:git:git:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git","purl":"pkg:deb/debian/git@1%3A2.47.3-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/git/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/git.postrm"},{"path":"/var/lib/dpkg/info/git.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git.list"},{"path":"/var/lib/dpkg/info/git.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git.postinst"},{"path":"/var/lib/dpkg/info/git.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git.preinst"},{"path":"/var/lib/dpkg/info/git.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2022-24975","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-07","epss":0.02624,"percentile":0.85015}],"risk":0.1312,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."},"relatedVulnerabilities":[{"id":"CVE-2022-24975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-07","epss":0.02624,"percentile":0.85015}],"urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."}]},{"artifact":{"id":"67c221344b7c7cbd","cpes":["cpe:2.3:a:git-man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git-man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git_man:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git-man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:git:git_man:1\\:2.47.3-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"git-man","purl":"pkg:deb/debian/git-man@1%3A2.47.3-0%2Bdeb13u1?arch=all&distro=debian-13.7&upstream=git","type":"deb","version":"1:2.47.3-0+deb13u1","language":"","licenses":["Apache-2.0","Artistic","BSD-3-clause","Boost","EDL-1.0","Expat","GPL","GPL-1+","GPL-2","GPL-2+","ISC","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","Zlib","dlmalloc","mingw-runtime"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/git-man/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/git-man/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git-man.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/git-man.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/git-man.list"}],"upstreams":[{"name":"git"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-24975","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"git","version":"1:2.47.3-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2022-24975","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-07","epss":0.02624,"percentile":0.85015}],"risk":0.1312,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."},"relatedVulnerabilities":[{"id":"CVE-2022-24975","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-24975","cwe":"CWE-668","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2022-24975","date":"2026-10-07","epss":0.02624,"percentile":0.85015}],"urls":["https://github.com/git/git/blob/2dc94da3744bfbbf145eca587a0f5ff480cc5867/Documentation/git-clone.txt#L185-L191","https://lore.kernel.org/git/xmqq4k14qe9g.fsf%40gitster.g/","https://www.aquasec.com/blog/undetected-hard-code-secrets-expose-corporations/","https://wwws.nightwatchcybersecurity.com/2022/02/11/gitbleed/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-24975","description":"The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59996","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59996","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-07","epss":0.0025,"percentile":0.14991}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."},"relatedVulnerabilities":[{"id":"CVE-2026-59996","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59996","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59996","date":"2026-10-07","epss":0.0025,"percentile":0.14991}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59996","description":"scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59995","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59995","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-07","epss":0.0025,"percentile":0.1499}],"risk":0.13,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."},"relatedVulnerabilities":[{"id":"CVE-2026-59995","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59995","cwe":"CWE-23","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59995","date":"2026-10-07","epss":0.0025,"percentile":0.1499}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59995","description":"sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server."}]},{"artifact":{"id":"614dd2dfa62b9595","cpes":["cpe:2.3:a:libldap2:libldap2:2.6.10\\+dfsg-1:*:*:*:*:*:*:*"],"name":"libldap2","purl":"pkg:deb/debian/libldap2@2.6.10%2Bdfsg-1?arch=amd64&distro=debian-13.7&upstream=openldap","type":"deb","version":"2.6.10+dfsg-1","language":"","licenses":["BSD-3-clause","BSD-3-clause-California","BSD-3-clause-variant","BSD-4-clause-California","Beerware","Expat","Expat-ISC","Expat-UNM","F5","FSF-unlimited","GPL-2","GPL-2+","GPL-3","GPL-3+","JCG","MIT-XC","NeoSoft-permissive","OpenLDAP-2.8","UMich","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libldap2/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libldap2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libldap2:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libldap2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openldap"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-15719","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openldap","version":"2.6.10+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-15719","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-07","epss":0.02515,"percentile":0.84329}],"risk":0.12575,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."},"relatedVulnerabilities":[{"id":"CVE-2020-15719","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:N","metrics":{"baseScore":4,"impactScore":5,"exploitabilityScore":5},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-15719","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2020-15719","date":"2026-10-07","epss":0.02515,"percentile":0.84329}],"urls":["http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00033.html","http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00059.html","https://access.redhat.com/errata/RHBA-2019:3674","https://bugs.openldap.org/show_bug.cgi?id=9266","https://bugzilla.redhat.com/show_bug.cgi?id=1740070","https://kc.mcafee.com/corporate/index?page=content&id=SB10365","https://www.oracle.com/security-alerts/cpuapr2022.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-15719","description":"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux."}]},{"artifact":{"id":"e3faa3de0a89f92d","cpes":["cpe:2.3:a:openjsf:fast-uri:3.1.7:*:*:*:*:node.js:*:*"],"name":"fast-uri","purl":"pkg:npm/fast-uri@3.1.7","type":"npm","version":"3.1.7","language":"javascript","licenses":["BSD-3-Clause"],"locations":[{"path":"/app/node_modules/fast-uri/package.json","layerID":"sha256:ef96f59daa16cd1e6faed99eb5bd88c964cfb57ab151517a273a2666d2accd52","accessPath":"/app/node_modules/fast-uri/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.1.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hrr3-gc8f-f4qj","versionConstraint":">=3.0.0,<3.1.8 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"fast-uri","version":"3.1.7"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-hrr3-gc8f-f4qj","fix":{"state":"fixed","versions":["3.1.8"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"3.1.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86472","cwe":"CWE-178","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-86472","date":"2026-10-07","epss":0.00253,"percentile":0.15355}],"risk":0.12397000000000001,"urls":["https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj","https://nvd.nist.gov/vuln/detail/CVE-2026-86472","https://github.com/fastify/fast-uri/commit/5dabb86732aa2a7655e258719970e61e12b6b4d1","https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/releases/tag/v2.4.7","https://github.com/fastify/fast-uri/releases/tag/v3.1.8","https://github.com/fastify/fast-uri/releases/tag/v4.1.5"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hrr3-gc8f-f4qj","description":"fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets"},"relatedVulnerabilities":[{"id":"CVE-2026-86472","cvss":[{"type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86472","cwe":"CWE-178","type":"Secondary","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}],"epss":[{"cve":"CVE-2026-86472","date":"2026-10-07","epss":0.00253,"percentile":0.15355}],"urls":["https://cna.openjsf.org/security-advisories.html","https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86472","description":"fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes to a literal A that is never folded. For a scheme-relative reference such as //host there is no scheme, so the host canonicalization that would normally repair this does not run, and parse, normalize, and equal then disagree on the same host. An application that makes a case-sensitive host decision on fast-uri output, for example a host allowlist or denylist that compares the parsed host or uses equal, can be steered past the check with a percent-encoded uppercase octet, and because hostnames are case-insensitive in DNS and HTTP the evading spelling still reaches the host the check meant to gate. The issue is fixed in fast-uri 2.4.7, 3.1.8, and 4.1.5, and users should upgrade to one of those versions or later. As a workaround, compare hosts case-insensitively by lowercasing the parsed host before any allowlist or denylist decision."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2007-2243","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2007-2243","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2243","date":"2026-10-07","epss":0.02472,"percentile":0.84034}],"risk":0.12360000000000002,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2007-2243","description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483."},"relatedVulnerabilities":[{"id":"CVE-2007-2243","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2007-2243","cwe":"CWE-287","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2007-2243","date":"2026-10-07","epss":0.02472,"percentile":0.84034}],"urls":["http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053906.html","http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053951.html","http://securityreason.com/securityalert/2631","http://www.osvdb.org/34600","http://www.securityfocus.com/bid/23601","https://exchange.xforce.ibmcloud.com/vulnerabilities/33794","https://security.netapp.com/advisory/ntap-20191107-0003/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2007-2243","description":"OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-9192","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-9192","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"risk":0.12235,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"},"relatedVulnerabilities":[{"id":"CVE-2019-9192","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-9192","cwe":"CWE-674","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-9192","date":"2026-10-07","epss":0.02447,"percentile":0.83863}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269","https://support.f5.com/csp/article/K26346590?utm_source=f5support&amp%3Butm_medium=RSS"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-9192","description":"In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern"}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"risk":0.12190000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service."},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-07","epss":0.00265,"percentile":0.16905}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19542","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-19542","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"risk":0.11978,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.  The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."},"relatedVulnerabilities":[{"id":"CVE-2026-19542","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19542","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-19542","date":"2026-10-07","epss":0.00226,"percentile":0.12172}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34506","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0018"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19542","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-35191","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-35191","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"risk":0.11959499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.  Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack.  CWE: CWE-440: Expected Behavior Violation   Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack.  If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed.  The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC.  FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE."},"relatedVulnerabilities":[{"id":"CVE-2026-35191","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-35191","cwe":"CWE-440","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-35191","date":"2026-10-07","epss":0.00357,"percentile":0.27384}],"urls":["https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239","https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5","https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-35191","description":"Issue summary: The OpenSSL QUIC server, when configured to not preform address\nvalidation, can be forced to count incoming packets multiple times in its\nunvalidated credit computation, leading to a violation of the RFC 9000\nunvalidated connection amplification limit of 3 times the amount of data\nreceived.\n\nImpact summary: A remote attacker able to spoof packets to a server using the\nOpenSSL QUIC implementation might use the server for an amplification of\na DDoS attack.\n\nCWE: CWE-440: Expected Behavior Violation \n\nDescription: OpenSSL's QUIC stack, when operating as a server, enforces client\naddress validation (RFC 9000, Section 8), to confirm the peer address is not\nused for a traffic amplification attack.  If this feature is disabled on the\nserver, the QUIC stack limits the amount of server data that can be sent to 3\ntimes the amount of data received from the peer address, until such time as the\nTLS handshake is completed.\n\nThe OpenSSL QUIC server, when operating in non-validation mode, adds the\nlength of the whole datagram received to the unvalidated credit limit when\nprocessing each QUIC packet in the datagram. A remote peer may,\nafter establishing a connection with an initial client hello frame, send a\nsubsequent datagram containing multiple QUIC packets, leading the server to\naccount the entire datagram length for each packet in the datagram, resulting\nin the server believing that the peer has sent more data than it actually has,\nthereby violating the 3x amplification limit mandated by the RFC.\n\nFIPS impact: no\nAs the QUIC stack lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"risk":0.11934,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-07","epss":0.00156,"percentile":0.04143}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59999","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59999","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-07","epss":0.00159,"percentile":0.04481}],"risk":0.11925,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."},"relatedVulnerabilities":[{"id":"CVE-2026-59999","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59999","cwe":"CWE-348","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59999","date":"2026-10-07","epss":0.00159,"percentile":0.04481}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59999","description":"In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not."}]},{"artifact":{"id":"ea4018933b7b4ef6","cpes":["cpe:2.3:a:libx11-6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_6:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-6:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_6:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-6","purl":"pkg:deb/debian/libx11-6@2%3A1.8.12-1?arch=amd64&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-6/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libx11-6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libx11-6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-07","epss":0.00199,"percentile":0.08889}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-07","epss":0.00199,"percentile":0.08889}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"25c33176f8e0362a","cpes":["cpe:2.3:a:libx11-data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11-data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11_data:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11-data:2\\:1.8.12-1:*:*:*:*:*:*:*","cpe:2.3:a:libx11:libx11_data:2\\:1.8.12-1:*:*:*:*:*:*:*"],"name":"libx11-data","purl":"pkg:deb/debian/libx11-data@2%3A1.8.12-1?arch=all&distro=debian-13.7&upstream=libx11","type":"deb","version":"2:1.8.12-1","language":"","licenses":["BSD-1-Clause","HPND","HPND-sell-variant","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libx11-data/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libx11-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libx11-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libx11-data.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libx11-data.list"}],"upstreams":[{"name":"libx11"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-94283","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libx11","version":"2:1.8.12-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-94283","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-07","epss":0.00199,"percentile":0.08889}],"risk":0.11442499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."},"relatedVulnerabilities":[{"id":"CVE-2026-94283","cvss":[{"type":"Secondary","source":"meissner@suse.de","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-94283","cwe":"CWE-125","type":"Secondary","source":"meissner@suse.de"}],"epss":[{"cve":"CVE-2026-94283","date":"2026-10-07","epss":0.00199,"percentile":0.08889}],"urls":["https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310/diffs?commit_id=42d0303f243002a9856c76060569a61893c670dd"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94283","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-75805","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-75805","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"risk":0.11433000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.   Impact summary: The NULL pointer dereference happens on a read which  leads to a crash and a Denial of Service for the affected client application.  CWE: CWE-476: NULL-pointer dereference  Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.  A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.  The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.  FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary."},"relatedVulnerabilities":[{"id":"CVE-2026-75805","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75805","cwe":"CWE-476","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-75805","date":"2026-10-07","epss":0.00222,"percentile":0.117}],"urls":["https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166","https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7","https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3","https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75805","description":"Issue summary: A CMP client that requests certificate revocation on the basis\nof a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when\nprocessing a crafted revocation response. \n\nImpact summary: The NULL pointer dereference happens on a read which \nleads to a crash and a Denial of Service for the affected client application.\n\nCWE: CWE-476: NULL-pointer dereference\n\nDescription: A CMP client revoking a certificate has to tell the server which\ncertificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the\ncertificate itself or its issuer name and serial number. This is\n'openssl cmp -cmd rr -csr <file>' on the command line, or\nOSSL_CMP_exec_RR_ses() with the certificate supplied via\nOSSL_CMP_CTX_set1_p10CSR() through the API.\n\nA CSR does not contain the issuer name and serial number of the certificate,\nso the client does not send them. A server may optionally name the\ncertificate it revoked in its response, and the client then compares that\nname against what it sent. Having sent neither an issuer name nor a serial\nnumber, it has nothing to compare against, and a server returning a specially\ncrafted name causes the client to read from a NULL pointer and crash.\n\nThe revocation response is checked for valid message protection before\nthe affected code is reached, so an attacker must be a malicious or\ncompromised CMP server, or a man-in-the-middle in possession of the\nsecret used for message protection. Clients that identify the certificate\nto be revoked by a certificate or by issuer and serial number rather\nthan by a PKCS#10 CSR are not affected.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2019-1010025","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2019-1010025","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"risk":0.11334999999999999,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."},"relatedVulnerabilities":[{"id":"CVE-2019-1010025","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-1010025","cwe":"CWE-330","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-1010025","date":"2026-10-07","epss":0.02267,"percentile":0.82503}],"urls":["https://security-tracker.debian.org/tracker/CVE-2019-1010025","https://sourceware.org/bugzilla/show_bug.cgi?id=22853","https://support.f5.com/csp/article/K06046097","https://support.f5.com/csp/article/K06046097?utm_source=f5support&amp%3Butm_medium=RSS","https://ubuntu.com/security/CVE-2019-1010025"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010025","description":"GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is \"ASLR bypass itself is not a vulnerability."}]},{"artifact":{"id":"21af26782f8669a0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.7&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-13757","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-13757","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-07","epss":0.00202,"percentile":0.09252}],"risk":0.11312000000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."},"relatedVulnerabilities":[{"id":"CVE-2026-13757","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13757","cwe":"CWE-674","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-13757","date":"2026-10-07","epss":0.00202,"percentile":0.09252}],"urls":["https://access.redhat.com/errata/RHSA-2026:37469","https://access.redhat.com/errata/RHSA-2026:38342","https://access.redhat.com/errata/RHSA-2026:49667","https://access.redhat.com/errata/RHSA-2026:49668","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54387","https://access.redhat.com/errata/RHSA-2026:54760","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:72394","https://access.redhat.com/errata/RHSA-2026:72395","https://access.redhat.com/errata/RHSA-2026:72399","https://access.redhat.com/errata/RHSA-2026:72470","https://access.redhat.com/errata/RHSA-2026:72475","https://access.redhat.com/errata/RHSA-2026:72476","https://access.redhat.com/errata/RHSA-2026:72502","https://access.redhat.com/security/cve/CVE-2026-13757","https://bugzilla.redhat.com/show_bug.cgi?id=2494556","https://github.com/advisories/GHSA-p2wm-69qx-x25w"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13757","description":"A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services."}]},{"artifact":{"id":"0af6f2d3417a318d","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-2\\+b1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/debian/libacl1@2.3.2-2%2Bb1?arch=amd64&distro=debian-13.7&upstream=acl%402.3.2-2","type":"deb","version":"2.3.2-2+b1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl","version":"2.3.2-2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"acl","version":"2.3.2-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-07","epss":0.00153,"percentile":0.03883}],"risk":0.11168999999999998,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-07","epss":0.00153,"percentile":0.03883}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"f5152615a12aeb3d","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/debian/bsdutils@1%3A2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"5c8cb5d5c2e5df78","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/debian/libblkid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bd4b70ba8c48d583","cpes":["cpe:2.3:a:liblastlog2-2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2-2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2_2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2-2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:liblastlog2:liblastlog2_2:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"liblastlog2-2","purl":"pkg:deb/debian/liblastlog2-2@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/liblastlog2-2/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/liblastlog2-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/liblastlog2-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cfe9c78846143096","cpes":["cpe:2.3:a:libmount1:libmount1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/debian/libmount1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"a6e51e84db754048","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/debian/libsmartcols1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"faedc3139e685610","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/debian/libuuid1@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"9db9d188fa9e89fc","cpes":["cpe:2.3:a:login:login:1\\:4.16.0-2\\+really2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/debian/login@1%3A4.16.0-2%2Breally2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux%402.41.5-0%2Bdeb13u1","type":"deb","version":"1:4.16.0-2+really2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.defs.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.conffiles"},{"path":"/var/lib/dpkg/info/login.defs.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.list"},{"path":"/var/lib/dpkg/info/login.defs.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.md5sums"},{"path":"/var/lib/dpkg/info/login.defs.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.defs.postinst"},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"util-linux","version":"2.41.5-0+deb13u1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"bd55752b0f187487","cpes":["cpe:2.3:a:mount:mount:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/debian/mount@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=util-linux","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"166978fa81223e72","cpes":["cpe:2.3:a:util-linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.41.5-0\\+deb13u1:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/debian/util-linux@2.41.5-0%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"2.41.5-0+deb13u1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-4-clause","BSLA","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","ISC","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"util-linux","version":"2.41.5-0+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"risk":0.11164999999999999,"urls":[],"severity":"High","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-07","epss":0.00154,"percentile":0.0396}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"6c23b5fbc804d426","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/debian/python3-pip-whl@25.1.1%2Bdfsg-1?arch=all&distro=debian-13.7&upstream=python-pip","type":"deb","version":"25.1.1+dfsg-1","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-1703","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python-pip","version":"25.1.1+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-1703","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1703","date":"2026-10-07","epss":0.00443,"percentile":0.36468}],"risk":0.11075,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-1703","description":"When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations."},"relatedVulnerabilities":[{"id":"CVE-2026-1703","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1703","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-1703","date":"2026-10-07","epss":0.00443,"percentile":0.36468}],"urls":["https://github.com/pypa/pip/commit/8e227a9be4faa9594e05d02ca05a413a2a4e7735","https://github.com/pypa/pip/pull/13777","https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1703","description":"When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-106585","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-106585","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-07","epss":0.00189,"percentile":0.07866}],"risk":0.10867499999999998,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."},"relatedVulnerabilities":[{"id":"CVE-2026-106585","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-106585","cwe":"CWE-409","type":"Primary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-106585","date":"2026-10-07","epss":0.00189,"percentile":0.07866}],"urls":["https://www.openssh.org/releasenotes.html#10.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-106585","description":"In sshd and ssh in OpenSSH before 10.6, there is no check for whether the maximum packet length is exceeded during decompression of highly compressed data."}]},{"artifact":{"id":"147b3d90c1d1a5d5","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.8.3-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/debian/libexpat1@2.8.3-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=expat","type":"deb","version":"2.8.3-1~deb13u1","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"expat","version":"2.8.3-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-07","epss":0.00203,"percentile":0.0936}],"risk":0.106575,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-07","epss":0.00203,"percentile":0.0936}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59998","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59998","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-07","epss":0.0018,"percentile":0.06885}],"risk":0.1035,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."},"relatedVulnerabilities":[{"id":"CVE-2026-59998","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.8,"impactScore":2.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59998","cwe":"CWE-573","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59998","date":"2026-10-07","epss":0.0018,"percentile":0.06885}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59998","description":"sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2020-14145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2020-14145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14145","date":"2026-10-07","epss":0.02057,"percentile":0.80689}],"risk":0.10285000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2020-14145","description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected."},"relatedVulnerabilities":[{"id":"CVE-2020-14145","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2020-14145","cwe":"CWE-203","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2020-14145","date":"2026-10-07","epss":0.02057,"percentile":0.80689}],"urls":["http://www.openwall.com/lists/oss-security/2020/12/02/1","https://anongit.mindrot.org/openssh.git/commit/?id=b3855ff053f5078ec3d3c653cdaedefaa5fc362d","https://docs.ssh-mitm.at/CVE-2020-14145.html","https://github.com/openssh/openssh-portable/compare/V_8_3_P1...V_8_4_P1","https://github.com/ssh-mitm/ssh-mitm/blob/master/ssh_proxy_server/plugins/session/cve202014145.py","https://security.gentoo.org/glsa/202105-35","https://security.netapp.com/advisory/ntap-20200709-0004/","https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2020-14145","description":"The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected."}]},{"artifact":{"id":"daa1f8dfeee1793b","cpes":["cpe:2.3:a:libgssapi-krb5-2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5-2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5_2:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi-krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi_krb5:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi-krb5-2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libgssapi:libgssapi_krb5_2:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgssapi-krb5-2","purl":"pkg:deb/debian/libgssapi-krb5-2@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgssapi-krb5-2/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libgssapi-krb5-2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libgssapi-krb5-2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"c5f7e9443917908e","cpes":["cpe:2.3:a:libk5crypto3:libk5crypto3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libk5crypto3","purl":"pkg:deb/debian/libk5crypto3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libk5crypto3/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libk5crypto3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libk5crypto3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"0d7d9accbe1a77b1","cpes":["cpe:2.3:a:libkrb5-3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5-3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5_3:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5-3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libkrb5:libkrb5_3:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5-3","purl":"pkg:deb/debian/libkrb5-3@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5-3/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libkrb5-3/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libkrb5-3:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"dcbb71b238b6d3d6","cpes":["cpe:2.3:a:libkrb5support0:libkrb5support0:1.21.3-5\\+deb13u1:*:*:*:*:*:*:*"],"name":"libkrb5support0","purl":"pkg:deb/debian/libkrb5support0@1.21.3-5%2Bdeb13u1?arch=amd64&distro=debian-13.7&upstream=krb5","type":"deb","version":"1.21.3-5+deb13u1","language":"","licenses":["sha256:936728f4181718f42951b881c1e8f1386bf6b2723c4fbc533c374d6f42c71816"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libkrb5support0/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libkrb5support0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libkrb5support0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"krb5"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2018-5709","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"krb5","version":"1.21.3-5+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-5709","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"risk":0.10245,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."},"relatedVulnerabilities":[{"id":"CVE-2018-5709","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-5709","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-5709","date":"2026-10-07","epss":0.02049,"percentile":0.80625}],"urls":["https://github.com/poojamnit/Kerberos-V5-1.16-Vulnerabilities/tree/master/Integer%20Overflow","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-5709","description":"An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data."}]},{"artifact":{"id":"6f2066ac1c2128fd","cpes":["cpe:2.3:a:libattr1:libattr1:1\\:2.5.2-3:*:*:*:*:*:*:*"],"name":"libattr1","purl":"pkg:deb/debian/libattr1@1%3A2.5.2-3?arch=amd64&distro=debian-13.7&upstream=attr","type":"deb","version":"1:2.5.2-3","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libattr1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libattr1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libattr1:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libattr1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libattr1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"attr"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54371","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"attr","version":"1:2.5.2-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54371","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-07","epss":0.00179,"percentile":0.06852}],"risk":0.10113499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."},"relatedVulnerabilities":[{"id":"CVE-2026-54371","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54371","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54371","date":"2026-10-07","epss":0.00179,"percentile":0.06852}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f","https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b","https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr","https://access.redhat.com/errata/RHSA-2026:34889","https://access.redhat.com/errata/RHSA-2026:56133","https://access.redhat.com/errata/RHSA-2026:59380","https://access.redhat.com/errata/RHSA-2026:60226","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:63135","https://access.redhat.com/errata/RHSA-2026:63138","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/security/cve/CVE-2026-54371","https://bugzilla.redhat.com/show_bug.cgi?id=2490283","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54371","description":"attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path."}]},{"artifact":{"id":"8a1ec6d9372df578","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg\\+really1.3.1-1\\+b1:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/debian/zlib1g@1%3A1.3.dfsg%2Breally1.3.1-1%2Bb1?arch=amd64&distro=debian-13.7&upstream=zlib%401%3A1.3.dfsg%2Breally1.3.1-1","type":"deb","version":"1:1.3.dfsg+really1.3.1-1+b1","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-27171","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"zlib","version":"1:1.3.dfsg+really1.3.1-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-27171","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-07","epss":0.00191,"percentile":0.08065}],"risk":0.10027499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."},"relatedVulnerabilities":[{"id":"CVE-2026-27171","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27171","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-27171","date":"2026-10-07","epss":0.00191,"percentile":0.08065}],"urls":["https://7asecurity.com/blog/2026/02/zlib-7asecurity-audit/","https://7asecurity.com/reports/pentest-report-zlib-RC1.1.pdf","https://github.com/madler/zlib/issues/904","https://github.com/madler/zlib/releases/tag/v1.3.2","https://ostif.org/zlib-audit-complete/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27171","description":"zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54875","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54875","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"risk":0.09849,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms.  Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar.  CWE: CWE-208: Observable Timing Discrepancy  Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel.  FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module.  OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V.  OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.  OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.  This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov.  -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov"},"relatedVulnerabilities":[{"id":"CVE-2026-54875","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54875","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54875","date":"2026-10-07","epss":0.00294,"percentile":0.2012}],"urls":["https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov"}]},{"artifact":{"id":"89e4a79e83ba4a33","cpes":["cpe:2.3:a:libpython3.13-minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_minimal:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-minimal","purl":"pkg:deb/debian/libpython3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"930c5e644d3d53cf","cpes":["cpe:2.3:a:libpython3.13-stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13-stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13_stdlib:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13-stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.13:libpython3.13_stdlib:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"libpython3.13-stdlib","purl":"pkg:deb/debian/libpython3.13-stdlib@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/libpython3.13-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libpython3.13-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"203cc3eac245dbd0","cpes":["cpe:2.3:a:python3.13:python3.13:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13","purl":"pkg:deb/debian/python3.13@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.list"},{"path":"/var/lib/dpkg/info/python3.13.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.postinst"},{"path":"/var/lib/dpkg/info/python3.13.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"77bc21d87dc8c5dd","cpes":["cpe:2.3:a:python3.13-minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_minimal:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_minimal:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-minimal","purl":"pkg:deb/debian/python3.13-minimal@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13-minimal/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-minimal.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.list"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.13-minimal.preinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.13-minimal.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-minimal.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"ab962375b151988c","cpes":["cpe:2.3:a:python3.13-venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13-venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13_venv:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13-venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*","cpe:2.3:a:python3.13:python3.13_venv:3.13.5-2\\+deb13u5:*:*:*:*:*:*:*"],"name":"python3.13-venv","purl":"pkg:deb/debian/python3.13-venv@3.13.5-2%2Bdeb13u5?arch=amd64&distro=debian-13.7&upstream=python3.13","type":"deb","version":"3.13.5-2+deb13u5","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.13/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3.13-venv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.13-venv.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.list"},{"path":"/var/lib/dpkg/info/python3.13-venv.postinst","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postinst"},{"path":"/var/lib/dpkg/info/python3.13-venv.postrm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.postrm"},{"path":"/var/lib/dpkg/info/python3.13-venv.prerm","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3.13-venv.prerm"}],"upstreams":[{"name":"python3.13"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python3.13","version":"3.13.5-2+deb13u5"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"risk":0.0981,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-07","epss":0.0018,"percentile":0.0691}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"86ca7491bc4976c9","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/debian/libc-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"00275ff991d2d7c8","cpes":["cpe:2.3:a:libc-dev-bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev-bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev_bin:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc-dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc_dev:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-dev-bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_dev_bin:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc-dev-bin","purl":"pkg:deb/debian/libc-dev-bin@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-dev-bin/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc-dev-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-dev-bin.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc-dev-bin.list"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"2dc9b457970cbedd","cpes":["cpe:2.3:a:libc6:libc6:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/debian/libc6@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"8aeff6e161c2995e","cpes":["cpe:2.3:a:libc6-dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6-dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6_dev:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6-dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:libc6:libc6_dev:2.41-12\\+deb13u4:*:*:*:*:*:*:*"],"name":"libc6-dev","purl":"pkg:deb/debian/libc6-dev@2.41-12%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=glibc","type":"deb","version":"2.41-12+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause-Berkeley","BSD-3-clause-Carnegie","BSD-3-clause-Oracle","BSD-3-clause-WIDE","BSD-like-Spencer","BSL-1.0","CORE-MATH","Carnegie","DEC","FSFAP","GPL-2","GPL-2+","GPL-2+-with-link-exception","GPL-3","GPL-3+","IBM","ISC","Inner-Net","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-2.1+-with-link-exception","LGPL-3","LGPL-3+","MIT-like-Lord","PCRE","SunPro","Unicode-DFS-2016","Univ-Coimbra","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6-dev/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libc6-dev/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libc6-dev:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"glibc","version":"2.41-12+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"risk":0.09781999999999998,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.  This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-07","epss":0.00292,"percentile":0.19898}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a604db0b806d9b55","cpes":["cpe:2.3:a:libncurses6:libncurses6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncurses6","purl":"pkg:deb/debian/libncurses6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libncurses6:amd64.md5sums","annotations":{"evidence":"supporting"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libncurses6/copyright","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"212a71fa16031fdf","cpes":["cpe:2.3:a:libncursesw6:libncursesw6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libncursesw6","purl":"pkg:deb/debian/libncursesw6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libncursesw6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/libncursesw6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"7402a3d31bb024db","cpes":["cpe:2.3:a:libtinfo6:libtinfo6:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"libtinfo6","purl":"pkg:deb/debian/libtinfo6@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libtinfo6/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libtinfo6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libtinfo6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"3f9378db54aaac9e","cpes":["cpe:2.3:a:ncurses-base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_base:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-base:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_base:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-base","purl":"pkg:deb/debian/ncurses-base@6.5%2B20250216-2?arch=all&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-base/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/ncurses-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.conffiles","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-base.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-base.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-base.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"e96cb50e09a471e0","cpes":["cpe:2.3:a:ncurses-bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses-bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses_bin:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses-bin:6.5\\+20250216-2:*:*:*:*:*:*:*","cpe:2.3:a:ncurses:ncurses_bin:6.5\\+20250216-2:*:*:*:*:*:*:*"],"name":"ncurses-bin","purl":"pkg:deb/debian/ncurses-bin@6.5%2B20250216-2?arch=amd64&distro=debian-13.7&upstream=ncurses","type":"deb","version":"6.5+20250216-2","language":"","licenses":["BSD-3-clause","MIT/X11","X11"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/ncurses-bin/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/ncurses-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/ncurses-bin.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/ncurses-bin.list"}],"upstreams":[{"name":"ncurses"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-6141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"ncurses","version":"6.5+20250216-2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2025-6141","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"risk":0.09603999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."},"relatedVulnerabilities":[{"id":"CVE-2025-6141","cvss":[{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-6141","cwe":"CWE-119","type":"Secondary","source":"cna@vuldb.com"},{"cve":"CVE-2025-6141","cwe":"CWE-121","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-6141","date":"2026-10-07","epss":0.00196,"percentile":0.0855}],"urls":["https://invisible-island.net/ncurses/NEWS.html#index-t20250329","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00107.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00109.html","https://lists.gnu.org/archive/html/bug-ncurses/2025-03/msg00114.html","https://vuldb.com/?ctiid.312610","https://vuldb.com/?id.312610","https://vuldb.com/?submit.593000","https://www.gnu.org/","https://cert-portal.siemens.com/productcert/html/ssa-089022.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-6141","description":"A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component."}]},{"artifact":{"id":"27a1dd3ab90f1486","cpes":["cpe:2.3:a:nodejs:nodejs:22.23.2-1nodesource1:*:*:*:*:*:*:*"],"name":"nodejs","purl":"pkg:deb/debian/nodejs@22.23.2-1nodesource1?arch=amd64&distro=debian-13.7","type":"deb","version":"22.23.2-1nodesource1","language":"","licenses":["Apache-2.0","Artistic-2.0","BSD-2-Clause","BSD-3-Clause","BlueOak-1.0.0","CC0-1.0","GPL-2.0-or-later","GPL-3.0-or-later","HPND-sell-variant","ICU","ISC","MIT","MIT-0","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/nodejs/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/nodejs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/nodejs.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/nodejs.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.list"},{"path":"/var/lib/dpkg/info/nodejs.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.postinst"},{"path":"/var/lib/dpkg/info/nodejs.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.preinst"},{"path":"/var/lib/dpkg/info/nodejs.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58045","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"nodejs","version":"22.23.2-1nodesource1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58045","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"support@hackerone.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58045","cwe":"CWE-400","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2026-58045","date":"2026-10-07","epss":0.00167,"percentile":0.05428}],"risk":0.09352,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58045","description":"A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.\r \r Repeated exploitation of this condition can result in a denial of service.\r \r This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**."},"relatedVulnerabilities":[{"id":"CVE-2026-58045","cvss":[{"type":"Secondary","source":"support@hackerone.com","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58045","cwe":"CWE-400","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2026-58045","date":"2026-10-07","epss":0.00167,"percentile":0.05428}],"urls":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58045","description":"A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.\r\n\r\nRepeated exploitation of this condition can result in a denial of service.\r\n\r\nThis vulnerability affects Node.js **22.x**, **24.x**, and **26.x**."}]},{"artifact":{"id":"642df124d4347f65","cpes":["cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:node.js:*:*","cpe:2.3:a:tar_project:tar:7.5.11:*:*:*:*:rust:*:*","cpe:2.3:a:isaacs:tar:7.5.11:*:*:*:*:node.js:*:*"],"name":"tar","purl":"pkg:npm/tar@7.5.11","type":"npm","version":"7.5.11","language":"javascript","licenses":["BlueOak-1.0.0"],"locations":[{"path":"/usr/lib/node_modules/npm/node_modules/tar/package.json","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/lib/node_modules/npm/node_modules/tar/package.json","annotations":{"evidence":"primary"}}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"7.5.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vmf3-w455-68vh","versionConstraint":"<=7.5.15 (semantic)"},"matcher":"javascript-matcher","searchedBy":{"package":{"name":"tar","version":"7.5.11"},"language":"javascript","namespace":"github:language:javascript"}}],"vulnerability":{"id":"GHSA-vmf3-w455-68vh","fix":{"state":"fixed","versions":["7.5.16"],"available":[{"date":"2026-06-15","kind":"first-observed","version":"7.5.16"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53655","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53655","date":"2026-10-07","epss":0.00156,"percentile":0.04204}],"risk":0.09281999999999999,"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"],"severity":"Medium","namespace":"github:language:javascript","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vmf3-w455-68vh","description":"node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)"},"relatedVulnerabilities":[{"id":"CVE-2026-53655","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-53655","cwe":"CWE-436","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-53655","date":"2026-10-07","epss":0.00156,"percentile":0.04204}],"urls":["https://github.com/isaacs/node-tar/security/advisories/GHSA-vmf3-w455-68vh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-53655","description":"node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16."}]},{"artifact":{"id":"f6e6d547b12be80a","cpes":["cpe:2.3:a:openssh-client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh-client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh_client:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh-client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*","cpe:2.3:a:openssh:openssh_client:1\\:10.0p1-7\\+deb13u4:*:*:*:*:*:*:*"],"name":"openssh-client","purl":"pkg:deb/debian/openssh-client@1%3A10.0p1-7%2Bdeb13u4?arch=amd64&distro=debian-13.7&upstream=openssh","type":"deb","version":"1:10.0p1-7+deb13u4","language":"","licenses":["BSD-2-clause","BSD-3-clause","Expat-with-advertising-restriction","Mazieres-BSD-style","OpenSSH","Powell-BSD-style","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssh-client/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/openssh-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.conffiles","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssh-client.postrm","layerID":"sha256:17e50ac0b36a3a97f75e7d401eefa84ce1c60680c141d2421f97fe43cf7eb8ae","accessPath":"/var/lib/dpkg/info/openssh-client.postrm"},{"path":"/var/lib/dpkg/info/openssh-client.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.list"},{"path":"/var/lib/dpkg/info/openssh-client.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.postinst"},{"path":"/var/lib/dpkg/info/openssh-client.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.preinst"},{"path":"/var/lib/dpkg/info/openssh-client.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/openssh-client.prerm"}],"upstreams":[{"name":"openssh"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59997","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssh","version":"1:10.0p1-7+deb13u4"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-59997","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-07","epss":0.00175,"percentile":0.06323}],"risk":0.091,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."},"relatedVulnerabilities":[{"id":"CVE-2026-59997","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59997","cwe":"CWE-1284","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-59997","date":"2026-10-07","epss":0.00175,"percentile":0.06323}],"urls":["https://marc.info/?l=openssh-unix-dev&m=178333966933090&w=2","https://www.openssh.org/releasenotes.html#10.4p1","https://www.openwall.com/lists/oss-security/2026/07/06/5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59997","description":"internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection."}]},{"artifact":{"id":"27a1dd3ab90f1486","cpes":["cpe:2.3:a:nodejs:nodejs:22.23.2-1nodesource1:*:*:*:*:*:*:*"],"name":"nodejs","purl":"pkg:deb/debian/nodejs@22.23.2-1nodesource1?arch=amd64&distro=debian-13.7","type":"deb","version":"22.23.2-1nodesource1","language":"","licenses":["Apache-2.0","Artistic-2.0","BSD-2-Clause","BSD-3-Clause","BlueOak-1.0.0","CC0-1.0","GPL-2.0-or-later","GPL-3.0-or-later","HPND-sell-variant","ICU","ISC","MIT","MIT-0","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/nodejs/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/nodejs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/nodejs.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/nodejs.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.list"},{"path":"/var/lib/dpkg/info/nodejs.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.postinst"},{"path":"/var/lib/dpkg/info/nodejs.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.preinst"},{"path":"/var/lib/dpkg/info/nodejs.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-58044","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"nodejs","version":"22.23.2-1nodesource1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-58044","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"support@hackerone.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58044","cwe":"CWE-444","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2026-58044","date":"2026-10-07","epss":0.00271,"percentile":0.17679}],"risk":0.090785,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-58044","description":"A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.\r \r Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.\r \r This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**."},"relatedVulnerabilities":[{"id":"CVE-2026-58044","cvss":[{"type":"Secondary","source":"support@hackerone.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58044","cwe":"CWE-444","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2026-58044","date":"2026-10-07","epss":0.00271,"percentile":0.17679}],"urls":["https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58044","description":"A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.\r\n\r\nNode.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**."}]},{"artifact":{"id":"27a1dd3ab90f1486","cpes":["cpe:2.3:a:nodejs:nodejs:22.23.2-1nodesource1:*:*:*:*:*:*:*"],"name":"nodejs","purl":"pkg:deb/debian/nodejs@22.23.2-1nodesource1?arch=amd64&distro=debian-13.7","type":"deb","version":"22.23.2-1nodesource1","language":"","licenses":["Apache-2.0","Artistic-2.0","BSD-2-Clause","BSD-3-Clause","BlueOak-1.0.0","CC0-1.0","GPL-2.0-or-later","GPL-3.0-or-later","HPND-sell-variant","ICU","ISC","MIT","MIT-0","Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/nodejs/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/nodejs/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/nodejs.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/nodejs.list","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.list"},{"path":"/var/lib/dpkg/info/nodejs.postinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.postinst"},{"path":"/var/lib/dpkg/info/nodejs.preinst","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.preinst"},{"path":"/var/lib/dpkg/info/nodejs.prerm","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/nodejs.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-48932","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"nodejs","version":"22.23.2-1nodesource1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-48932","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","source":"support@hackerone.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48932","cwe":"CWE-444","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2026-48932","date":"2026-10-07","epss":0.00271,"percentile":0.17678}],"risk":0.090785,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-48932","description":"A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.\r \r Node.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.\r \r This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**."},"relatedVulnerabilities":[{"id":"CVE-2026-48932","cvss":[{"type":"Secondary","source":"support@hackerone.com","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-48932","cwe":"CWE-444","type":"Secondary","source":"support@hackerone.com"}],"epss":[{"cve":"CVE-2026-48932","date":"2026-10-07","epss":0.00271,"percentile":0.17678}],"urls":["https://hackerone.com/reports/3564941"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-48932","description":"A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the original body to a reused backend connection.\r\n\r\nNode.js can omit headers beyond `maxHeadersCount` / `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinct`, while still using those omitted headers internally for HTTP message framing. In particular, `Content-Length` can be hidden from userland while the request body is still delivered.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**."}]},{"artifact":{"id":"6004b03bf692a003","cpes":["cpe:2.3:a:libbz2-1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2-1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2_1.0:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2-1.0:1.0.8-6:*:*:*:*:*:*:*","cpe:2.3:a:libbz2:libbz2_1.0:1.0.8-6:*:*:*:*:*:*:*"],"name":"libbz2-1.0","purl":"pkg:deb/debian/libbz2-1.0@1.0.8-6?arch=amd64&distro=debian-13.7&upstream=bzip2","type":"deb","version":"1.0.8-6","language":"","licenses":["BSD-variant","GPL-2"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libbz2-1.0/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libbz2-1.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libbz2-1.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"bzip2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-42250","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"bzip2","version":"1.0.8-6"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-42250","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-07","epss":0.00182,"percentile":0.07165}],"risk":0.08918,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).  This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"},"relatedVulnerabilities":[{"id":"CVE-2026-42250","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42250","cwe":"CWE-787","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-42250","date":"2026-10-07","epss":0.00182,"percentile":0.07165}],"urls":["https://cert.pl/en/posts/2026/05/CVE-2026-42250/","https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/","https://sourceware.org/bzip2/","https://sourceware.org/cgit/bzip2/commit/?id=35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42250","description":"bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).\n\nThis issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67"}]},{"artifact":{"id":"32738b09752b2320","cpes":["cpe:2.3:a:libgcrypt20:libgcrypt20:1.11.0-7\\+deb13u1:*:*:*:*:*:*:*"],"name":"libgcrypt20","purl":"pkg:deb/debian/libgcrypt20@1.11.0-7%2Bdeb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"1.11.0-7+deb13u1","language":"","licenses":["sha256:4feae258cab1ad4743fb569a77e0b2a5b7a0199520bdbc0a613916291b9aa8a8"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libgcrypt20/copyright","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/usr/share/doc/libgcrypt20/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","layerID":"sha256:c8fb9dd6c97ef456d92c52a8a718cae4c66806ed0a394d10c78bed02e242b64f","accessPath":"/var/lib/dpkg/info/libgcrypt20:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6829","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"libgcrypt20","version":"1.11.0-7+deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2018-6829","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-07","epss":0.01777,"percentile":0.77534}],"risk":0.08885000000000001,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."},"relatedVulnerabilities":[{"id":"CVE-2018-6829","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6829","cwe":"CWE-327","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6829","date":"2026-10-07","epss":0.01777,"percentile":0.77534}],"urls":["https://github.com/weikengchen/attack-on-libgcrypt-elgamal","https://github.com/weikengchen/attack-on-libgcrypt-elgamal/wiki","https://lists.gnupg.org/pipermail/gcrypt-devel/2018-February/004394.html","https://www.oracle.com/security-alerts/cpujan2020.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6829","description":"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation."}]},{"artifact":{"id":"3f14f57e5d4140a1","cpes":["cpe:2.3:a:libssl3t64:libssl3t64:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"libssl3t64","purl":"pkg:deb/debian/libssl3t64@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libssl3t64/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libssl3t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libssl3t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"8ad59b627628fd53","cpes":["cpe:2.3:a:openssl:openssl:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl","purl":"pkg:deb/debian/openssl@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/openssl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.conffiles","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.list"},{"path":"/var/lib/dpkg/info/openssl.postinst","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/openssl.postinst"}],"upstreams":[]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"4b8c5bd5be8079b2","cpes":["cpe:2.3:a:openssl-provider-legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider-legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider_legacy:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl-provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl_provider:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl-provider-legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:openssl:openssl_provider_legacy:3.5.7-1\\~deb13u2:*:*:*:*:*:*:*"],"name":"openssl-provider-legacy","purl":"pkg:deb/debian/openssl-provider-legacy@3.5.7-1~deb13u2?arch=amd64&distro=debian-13.7&upstream=openssl","type":"deb","version":"3.5.7-1~deb13u2","language":"","licenses":["Apache-2.0","Artistic","GPL-1","GPL-1+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/openssl-provider-legacy/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/openssl-provider-legacy/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/openssl-provider-legacy.list","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/openssl-provider-legacy.list"}],"upstreams":[{"name":"openssl"}]},"matchDetails":[{"fix":{"suggestedVersion":"3.5.7-1~deb13u3"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54872","versionConstraint":"< 3.5.7-1~deb13u3 (deb)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"openssl","version":"3.5.7-1~deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-54872","fix":{"state":"fixed","versions":["3.5.7-1~deb13u3"],"available":[{"date":"2026-09-30","kind":"advisory","version":"3.5.7-1~deb13u3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"risk":0.08810499999999999,"urls":[],"severity":"Low","namespace":"debian:distro:debian:13","advisories":[{"id":"DSA-6531-1","link":"https://security-tracker.debian.org/tracker/DSA-6531-1"}],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.  Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.  CWE: CWE-208: Observable Timing Discrepancy  Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.  The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.  Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.  The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.  FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path."},"relatedVulnerabilities":[{"id":"CVE-2026-54872","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54872","cwe":"CWE-208","type":"Secondary","source":"openssl-security@openssl.org"}],"epss":[{"cve":"CVE-2026-54872","date":"2026-10-07","epss":0.00263,"percentile":0.16569}],"urls":["https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179","https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb","https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd","https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471","https://openssl-library.org/news/secadv/20260929.txt"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54872","description":"Issue summary: The generic elliptic-curve scalar multiplication used for\nECDSA and SM2 signature operations with curves that do not have a dedicated\nimplementation leaks information about the secret nonce through timing.\n\nImpact summary: An attacker able to measure signing times may learn\ninformation about the per-signature secret nonce, which over many signatures\ncan, via a lattice / Hidden Number Problem attack, lead to recovery of the\nprivate key.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: The generic elliptic-curve scalar multiplication used for\ncurves that do not have a dedicated constant-time implementation pads the\nsecret scalar with non-constant-time BIGNUM operations, so the time taken\ndepends on the value of the secret scalar derived from the ECDSA and SM2 nonce.\n\nThe leak is very small; observing it requires a large number of\nmeasurements. The effect is largest for curves whose group order lies\non a machine-word boundary, such as brainpoolP384r1.\n\nApplications using ECDSA signing over the Brainpool and other generic prime\ncurves, and SM2 signing on platforms that use the generic implementation,\nare vulnerable to this issue.\n\nThe NIST curves P-256, P-384 and P-521 use dedicated constant-time\nimplementations and are not affected.\n\nFIPS Impact: no\nThe FIPS modules are not affected: the approved NIST curves used in the FIPS\nprovider have dedicated constant-time implementations and do not use the\naffected code path."}]},{"artifact":{"id":"6c23b5fbc804d426","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/debian/python3-pip-whl@25.1.1%2Bdfsg-1?arch=all&distro=debian-13.7&upstream=python-pip","type":"deb","version":"25.1.1+dfsg-1","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6357","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python-pip","version":"25.1.1+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-6357","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6357","date":"2026-10-07","epss":0.00171,"percentile":0.05864}],"risk":0.08806499999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-6357","description":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation."},"relatedVulnerabilities":[{"id":"CVE-2026-6357","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6357","cwe":"CWE-829","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6357","date":"2026-10-07","epss":0.00171,"percentile":0.05864}],"urls":["https://github.com/pypa/pip/pull/13923","https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/#security-fixes","http://www.openwall.com/lists/oss-security/2026/04/27/7"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6357","description":"pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip CLI. The patch changes self-update functionality to run before wheels are installed to prevent newly-installed modules from being imported shortly after the installation of a wheel package. Users should still review package contents prior to installation."}]},{"artifact":{"id":"6c23b5fbc804d426","cpes":["cpe:2.3:a:python3-pip-whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip-whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip_whl:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3-pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3_pip:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pip-whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pip_whl:25.1.1\\+dfsg-1:*:*:*:*:*:*:*"],"name":"python3-pip-whl","purl":"pkg:deb/debian/python3-pip-whl@25.1.1%2Bdfsg-1?arch=all&distro=debian-13.7&upstream=python-pip","type":"deb","version":"25.1.1+dfsg-1","language":"","licenses":["Apache-2.0","BSD-2","BSD-3","Expat","ISC","MPL-2","MPL-2.0","Python"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pip-whl/copyright","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/usr/share/doc/python3-pip-whl/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.md5sums","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pip-whl.list","layerID":"sha256:aefd4ffe12efe21c1e9d15ee1f7179c4919f35880643cbde391e114e60afe11e","accessPath":"/var/lib/dpkg/info/python3-pip-whl.list"}],"upstreams":[{"name":"python-pip"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"python-pip","version":"25.1.1+dfsg-1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3219","date":"2026-10-07","epss":0.0018,"percentile":0.06988}],"risk":0.08639999999999999,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-3219","description":"pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both."},"relatedVulnerabilities":[{"id":"CVE-2026-3219","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3219","cwe":"CWE-434","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3219","date":"2026-10-07","epss":0.0018,"percentile":0.06988}],"urls":["https://github.com/pypa/pip/pull/13870","https://mail.python.org/archives/list/security-announce@python.org/thread/QAJ5JIVWWCAJ4EZL2FP5MOOW35JS7LRJ/","http://www.openwall.com/lists/oss-security/2026/04/20/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3219","description":"pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing \"incorrect\" files according to the filename of the archive. New behavior only proceeds with installation if the file identifies uniquely as a ZIP or tar archive, not as both."}]},{"artifact":{"id":"653895736ec05e51","cpes":["cpe:2.3:a:apache2-utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2-utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2_utils:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2-utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:apache2:apache2_utils:2.4.68-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"apache2-utils","purl":"pkg:deb/debian/apache2-utils@2.4.68-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=apache2","type":"deb","version":"2.4.68-1~deb13u1","language":"","licenses":["Apache-2.0","BSD-2-clause-Darwin","BSD-3-clause-Cambridge","BSD-3-clause-Smrgrav","Cisco","Custom","Expat","GPL-2","GPL-2+","GPL-3","GPL-3+","Haines","MD5","PCRE","Zeus"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/apache2-utils/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/apache2-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/apache2-utils.list","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/apache2-utils.list"}],"upstreams":[{"name":"apache2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2003-1307","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"apache2","version":"2.4.68-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2003-1307","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2003-1307","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1307","date":"2026-10-07","epss":0.01724,"percentile":0.7681}],"risk":0.0862,"urls":[],"severity":"Negligible","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2003-1307","description":"The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port.  NOTE: the PHP developer has disputed this vulnerability, saying \"The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."},"relatedVulnerabilities":[{"id":"CVE-2003-1307","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:S/C:P/I:P/A:P","metrics":{"baseScore":4.3,"impactScore":6.5,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2003-1307","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2003-1307","date":"2026-10-07","epss":0.01724,"percentile":0.7681}],"urls":["http://bugs.php.net/38915","http://hackerdom.ru/~dimmo/phpexpl.c","http://www.securityfocus.com/archive/1/348368","http://www.securityfocus.com/archive/1/449234/100/0/threaded","http://www.securityfocus.com/archive/1/449298/100/0/threaded","http://www.securityfocus.com/bid/9302"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2003-1307","description":"The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port.  NOTE: the PHP developer has disputed this vulnerability, saying \"The opened file descriptors are opened by Apache. It is the job of Apache to protect them ... Not a bug in PHP."}]},{"artifact":{"id":"21af26782f8669a0","cpes":["cpe:2.3:a:libp11-kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11-kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11_kit0:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11-kit0:0.25.5-3:*:*:*:*:*:*:*","cpe:2.3:a:libp11:libp11_kit0:0.25.5-3:*:*:*:*:*:*:*"],"name":"libp11-kit0","purl":"pkg:deb/debian/libp11-kit0@0.25.5-3?arch=amd64&distro=debian-13.7&upstream=p11-kit","type":"deb","version":"0.25.5-3","language":"","licenses":["Apache-2.0","BSD-3-clause","FSFAP","FSFULLR","GPL-2+","GPL-3+","ISC","LGPL-2.1","LGPL-2.1+","X11","customFSFUL","customFSFULLRWD"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libp11-kit0/copyright","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/usr/share/doc/libp11-kit0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","layerID":"sha256:a2f411bde3226f34f2218cf3e318f1de7d5315bd0462390e0a25037a95f16899","accessPath":"/var/lib/dpkg/info/libp11-kit0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"p11-kit"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18938","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"p11-kit","version":"0.25.5-3"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-18938","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-07","epss":0.00152,"percentile":0.03823}],"risk":0.08512000000000002,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."},"relatedVulnerabilities":[{"id":"CVE-2026-18938","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18938","cwe":"CWE-122","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18938","date":"2026-10-07","epss":0.00152,"percentile":0.03823}],"urls":["https://access.redhat.com/security/cve/CVE-2026-18938","https://bugzilla.redhat.com/show_bug.cgi?id=2478995"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18938","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems."}]},{"artifact":{"id":"4bf5c63b07c21ab3","cpes":["cpe:2.3:a:libsqlite3-0:libsqlite3-0:3.46.1-7\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3-0:libsqlite3_0:3.46.1-7\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3-0:3.46.1-7\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3_0:libsqlite3_0:3.46.1-7\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3-0:3.46.1-7\\+deb13u2:*:*:*:*:*:*:*","cpe:2.3:a:libsqlite3:libsqlite3_0:3.46.1-7\\+deb13u2:*:*:*:*:*:*:*"],"name":"libsqlite3-0","purl":"pkg:deb/debian/libsqlite3-0@3.46.1-7%2Bdeb13u2?arch=amd64&distro=debian-13.7&upstream=sqlite3","type":"deb","version":"3.46.1-7+deb13u2","language":"","licenses":["GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsqlite3-0/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsqlite3-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsqlite3-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"sqlite3"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-50812","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"sqlite3","version":"3.46.1-7+deb13u2"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-50812","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-07","epss":0.0016,"percentile":0.04566}],"risk":0.084,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."},"relatedVulnerabilities":[{"id":"CVE-2026-50812","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-50812","cwe":"CWE-476","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-50812","date":"2026-10-07","epss":0.0016,"percentile":0.04566}],"urls":["https://gist.github.com/junius-sec/bb556f333957c5226dede314db0e9e91","https://github.com/sqlite/sqlite/commit/b869ed6b067d623cb1383549f2a18aa35508385d","https://sqlite.org/src/info/e807d4e3798efd53"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-50812","description":"A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer."}]},{"artifact":{"id":"a4f6a5e4d7c82cbb","cpes":["cpe:2.3:a:libsystemd-shared:libsystemd-shared:257.13-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd-shared:libsystemd_shared:257.13-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd-shared:257.13-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd_shared:libsystemd_shared:257.13-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd-shared:257.13-1\\~deb13u1:*:*:*:*:*:*:*","cpe:2.3:a:libsystemd:libsystemd_shared:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd-shared","purl":"pkg:deb/debian/libsystemd-shared@257.13-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd-shared/copyright","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/usr/share/doc/libsystemd-shared/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/libsystemd-shared:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"8bfae933fd40ea5d","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/debian/libsystemd0@257.13-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"4468281f476fc994","cpes":["cpe:2.3:a:libudev1:libudev1:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/debian/libudev1@257.13-1~deb13u1?arch=amd64&distro=debian-13.7&upstream=systemd","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:a6dc765193a52cbaede3c93a9ff48b9540948dd0774bbe7031fcb5847606f9ac","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]},{"artifact":{"id":"32b710ba4f5ba5a6","cpes":["cpe:2.3:a:systemd:systemd:257.13-1\\~deb13u1:*:*:*:*:*:*:*"],"name":"systemd","purl":"pkg:deb/debian/systemd@257.13-1~deb13u1?arch=amd64&distro=debian-13.7","type":"deb","version":"257.13-1~deb13u1","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd/copyright","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/usr/share/doc/systemd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.conffiles","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.md5sums","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd.list","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.list"},{"path":"/var/lib/dpkg/info/systemd.postinst","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.postinst"},{"path":"/var/lib/dpkg/info/systemd.postrm","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.postrm"},{"path":"/var/lib/dpkg/info/systemd.preinst","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.preinst"},{"path":"/var/lib/dpkg/info/systemd.prerm","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.prerm"},{"path":"/var/lib/dpkg/info/systemd.triggers","layerID":"sha256:ea400edc8f7108fc548c87878bf5b598c3baef9871542988b759c8db59dc6872","accessPath":"/var/lib/dpkg/info/systemd.triggers"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15059","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"debian","version":"13.7"},"package":{"name":"systemd","version":"257.13-1~deb13u1"},"namespace":"debian:distro:debian:13"}}],"vulnerability":{"id":"CVE-2026-15059","fix":{"state":"wont-fix","versions":[]},"cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"risk":0.08347500000000001,"urls":[],"severity":"Medium","namespace":"debian:distro:debian:13","advisories":[],"dataSource":"https://security-tracker.debian.org/tracker/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."},"relatedVulnerabilities":[{"id":"CVE-2026-15059","cvss":[{"type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15059","cwe":"CWE-22","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"},{"cve":"CVE-2026-15059","cwe":"CWE-59","type":"Secondary","source":"98a521c5-3a3e-4e2b-bc27-002067e0463c"}],"epss":[{"cve":"CVE-2026-15059","date":"2026-10-07","epss":0.00159,"percentile":0.04462}],"urls":["https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15059","description":"Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation."}]}],"grade":"F","score":"0.00","as_of":"2026-10-08T17:29:21.776Z","grype_db_version":"2026-10-08T06:33:47.000Z"}