{"grype_matches":[{"artifact":{"id":"63479789c224b9e2","cpes":["cpe:2.3:a:apache:commons-lang3:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_lang3:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:3.12.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:lang3:3.12.0:*:*:*:*:*:*:*"],"name":"commons-lang3","purl":"pkg:maven/org.apache.commons/commons-lang3@3.12.0","type":"java-archive","version":"3.12.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"org.apache.commons","virtualPath":"/app/ubooquity/Ubooquity.jar:commons-lang3-3.12.0.jar","manifestName":"","pomArtifactID":"commons-lang3","archiveDigests":[{"value":"c6842c86792ff03b9f1d1fe2aab8dc23aa6c6f0e","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:commons-lang3-3.12.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"3.18.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j288-q9x7-2f5v","versionConstraint":">=3.0,<3.18.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.apache.commons:commons-lang3","version":"3.12.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j288-q9x7-2f5v","fix":{"state":"fixed","versions":["3.18.0"],"available":[{"date":"2025-07-12","kind":"first-observed","version":"3.18.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"risk":1.409325,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-48924","https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html","http://www.openwall.com/lists/oss-security/2025/07/11/1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j288-q9x7-2f5v","description":"Apache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs"},"relatedVulnerabilities":[{"id":"CVE-2025-48924","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-48924","cwe":"CWE-674","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2025-48924","date":"2026-10-08","epss":0.02451,"percentile":0.83897}],"urls":["https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1","http://www.openwall.com/lists/oss-security/2025/07/11/1","https://lists.debian.org/debian-lts-announce/2025/08/msg00000.html","https://lists.debian.org/debian-lts-announce/2025/08/msg00026.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00032.html","https://lists.debian.org/debian-lts-announce/2025/09/msg00036.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-48924","description":"Uncontrolled Recursion vulnerability in Apache Commons Lang.\n\nThis issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.\n\nThe methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a \nStackOverflowError could cause an application to stop.\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue."}]},{"artifact":{"id":"84734ecc72f4f871","cpes":["cpe:2.3:a:com.github.junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:org.sonatype.oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:github:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*"],"name":"junrar","purl":"pkg:maven/com.github.junrar/junrar@3.0.1-Ubooquity","type":"java-archive","version":"3.0.1-Ubooquity","language":"java","licenses":["UnRar License"],"metadata":{"pomGroupID":"com.github.junrar","virtualPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","manifestName":"","pomArtifactID":"junrar","archiveDigests":[{"value":"1723f2e3c340f769902fa5bb4620d16155ab7314","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"7.4.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-m6cj-93v6-cvr5","versionConstraint":"<7.4.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.github.junrar:junrar","version":"3.0.1-Ubooquity"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-m6cj-93v6-cvr5","fix":{"state":"fixed","versions":["7.4.1"],"available":[{"date":"2022-02-01","kind":"first-observed","version":"7.4.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23596","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23596","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23596","date":"2026-10-08","epss":0.01632,"percentile":0.75517}],"risk":1.2240000000000002,"urls":["https://github.com/junrar/junrar/security/advisories/GHSA-m6cj-93v6-cvr5","https://github.com/junrar/junrar/issues/73","https://github.com/junrar/junrar/commit/7b16b3d90b91445fd6af0adfed22c07413d4fab7","https://nvd.nist.gov/vuln/detail/CVE-2022-23596"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-m6cj-93v6-cvr5","description":"Junrar vulnerable to infinite loop via extracting carefully crafted RAR archive"},"relatedVulnerabilities":[{"id":"CVE-2022-23596","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-23596","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-23596","cwe":"CWE-835","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-23596","date":"2026-10-08","epss":0.01632,"percentile":0.75517}],"urls":["https://github.com/junrar/junrar/commit/7b16b3d90b91445fd6af0adfed22c07413d4fab7","https://github.com/junrar/junrar/issues/73","https://github.com/junrar/junrar/security/advisories/GHSA-m6cj-93v6-cvr5"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-23596","description":"Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users. The problem is patched in 7.4.1. There are no known workarounds and users are advised to upgrade as soon as possible."}]},{"artifact":{"id":"adebc200857afbec","cpes":["cpe:2.3:a:apache:commons-io:2.13.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_io:2.13.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons:2.13.0:*:*:*:*:*:*:*"],"name":"commons-io","purl":"pkg:maven/commons-io/commons-io@2.13.0","type":"java-archive","version":"2.13.0","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"commons-io","virtualPath":"/app/ubooquity/Ubooquity.jar:commons-io-2.13.0.jar","manifestName":"","pomArtifactID":"commons-io","archiveDigests":[{"value":"8bb2bc9b4df17e2411533a0708a69f983bf5e83b","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:commons-io-2.13.0.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.14.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-78wr-2p64-hpwj","versionConstraint":">=2.0,<2.14.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"commons-io:commons-io","version":"2.13.0"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-78wr-2p64-hpwj","fix":{"state":"fixed","versions":["2.14.0"],"available":[{"date":"2024-10-04","kind":"first-observed","version":"2.14.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-47554","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-47554","date":"2026-10-08","epss":0.01315,"percentile":0.69883}],"risk":1.0257,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-47554","https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1","http://www.openwall.com/lists/oss-security/2024/10/03/2","https://security.netapp.com/advisory/ntap-20250131-0010"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-78wr-2p64-hpwj","description":"Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader"},"relatedVulnerabilities":[{"id":"CVE-2024-47554","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-47554","cwe":"CWE-400","type":"Secondary","source":"security@apache.org"}],"epss":[{"cve":"CVE-2024-47554","date":"2026-10-08","epss":0.01315,"percentile":0.69883}],"urls":["https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1","http://www.openwall.com/lists/oss-security/2024/10/03/2","https://security.netapp.com/advisory/ntap-20250131-0010/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-47554","description":"Uncontrolled Resource Consumption vulnerability in Apache Commons IO.\n\nThe org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.\n\n\nThis issue affects Apache Commons IO: from 2.0 before 2.14.0.\n\nUsers are recommended to upgrade to version 2.14.0 or later, which fixes the issue."}]},{"artifact":{"id":"ef6ba7fd852d826b","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:http:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"06eb099ce51496de87ecfe9b8c62c2e8f3f5e848","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"11.0.29"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-355h-qmc2-wpwf","versionConstraint":">=11.0.0,<=11.0.28 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-355h-qmc2-wpwf","fix":{"state":"fixed","versions":["11.0.29"],"available":[{"date":"2026-08-15","kind":"first-observed","version":"11.0.29"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-2332","date":"2026-10-08","epss":0.01305,"percentile":0.69668}],"risk":0.972225,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://nvd.nist.gov/vuln/detail/CVE-2026-2332","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://w4ke.info/2025/06/18/funky-chunks.html","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://access.redhat.com/security/cve/CVE-2026-2332","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:10175"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-355h-qmc2-wpwf","description":"Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing"},"relatedVulnerabilities":[{"id":"CVE-2026-2332","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2026-2332","cwe":"CWE-444","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-2332","date":"2026-10-08","epss":0.01305,"percentile":0.69668}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf","https://gitlab.eclipse.org/security/cve-assignment/-/issues/89","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:20568","https://access.redhat.com/errata/RHSA-2026:21773","https://access.redhat.com/errata/RHSA-2026:22453","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:50221","https://access.redhat.com/errata/RHSA-2026:50222","https://access.redhat.com/errata/RHSA-2026:50223","https://access.redhat.com/errata/RHSA-2026:50263","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/security/cve/CVE-2026-2332","https://bugzilla.redhat.com/show_bug.cgi?id=2458187","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-2332","description":"In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request."}]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rmj7-2vxq-3g9f","versionConstraint":">=2.10.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-rmj7-2vxq-3g9f","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"risk":0.95628,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://nvd.nist.gov/vuln/detail/CVE-2026-54513","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rmj7-2vxq-3g9f","description":"jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)"},"relatedVulnerabilities":[{"id":"CVE-2026-54513","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54513","cwe":"CWE-184","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54513","date":"2026-10-08","epss":0.01226,"percentile":0.67932}],"urls":["https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5","https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e","https://github.com/FasterXML/jackson-databind/issues/5981","https://github.com/FasterXML/jackson-databind/issues/5983","https://github.com/FasterXML/jackson-databind/pull/5984","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f","https://access.redhat.com/errata/RHSA-2026:36839","https://access.redhat.com/errata/RHSA-2026:40895","https://access.redhat.com/errata/RHSA-2026:41951","https://access.redhat.com/errata/RHSA-2026:43218","https://access.redhat.com/errata/RHSA-2026:43400","https://access.redhat.com/errata/RHSA-2026:44061","https://access.redhat.com/errata/RHSA-2026:44062","https://access.redhat.com/errata/RHSA-2026:44063","https://access.redhat.com/errata/RHSA-2026:44064","https://access.redhat.com/errata/RHSA-2026:44065","https://access.redhat.com/errata/RHSA-2026:44066","https://access.redhat.com/errata/RHSA-2026:44271","https://access.redhat.com/errata/RHSA-2026:48095","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:50846","https://access.redhat.com/errata/RHSA-2026:50847","https://access.redhat.com/errata/RHSA-2026:50848","https://access.redhat.com/errata/RHSA-2026:50849","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54622","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:66545","https://access.redhat.com/security/cve/CVE-2026-54513","https://bugzilla.redhat.com/show_bug.cgi?id=2492010","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54513","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j3rv-43j4-c7qm","versionConstraint":">=2.10.0,<=2.18.7 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j3rv-43j4-c7qm","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"risk":0.7792200000000001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://nvd.nist.gov/vuln/detail/CVE-2026-54512"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j3rv-43j4-c7qm","description":"jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation"},"relatedVulnerabilities":[{"id":"CVE-2026-54512","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.1,"impactScore":5.9,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54512","cwe":"CWE-184","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-54512","cwe":"CWE-502","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54512","date":"2026-10-08","epss":0.00999,"percentile":0.61664}],"urls":["https://github.com/FasterXML/jackson-databind/commit/434d6c511de7fdd9872f29157aafb6162d12d8d5","https://github.com/FasterXML/jackson-databind/issues/5988","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-j3rv-43j4-c7qm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54512","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3805","versionConstraint":">= 8.13.0, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3805","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3805","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3805","date":"2026-10-08","epss":0.00988,"percentile":0.61304}],"risk":0.741,"urls":["https://curl.se/docs/CVE-2026-3805.html","https://curl.se/docs/CVE-2026-3805.json","https://hackerone.com/reports/3591944","http://www.openwall.com/lists/oss-security/2026/03/11/4"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3805","description":"When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-19931","versionConstraint":">= 7.64.1, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-19931","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-19931","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19931","date":"2026-10-08","epss":0.00747,"percentile":0.53447}],"risk":0.70218,"urls":["https://curl.se/docs/CVE-2026-19931.html","https://curl.se/docs/CVE-2026-19931.json","https://hackerone.com/reports/3923520"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19931","description":"A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80231","versionConstraint":">= 7.71.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80231","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80231","cwe":"CWE-488","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80231","date":"2026-10-08","epss":0.00898,"percentile":0.58384}],"risk":0.6735,"urls":["https://curl.se/docs/CVE-2026-80231.html","https://curl.se/docs/CVE-2026-80231.json","https://hackerone.com/reports/3969368"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80231","description":"A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup\nfor a given hostname even when using a different Native CA Store setting\n(`CURLSSLOPT_NATIVE_CA`) than when the connection was created."},"relatedVulnerabilities":[]},{"artifact":{"id":"ef6ba7fd852d826b","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:http:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"06eb099ce51496de87ecfe9b8c62c2e8f3f5e848","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"11.0.16"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hmr7-m48g-48f6","versionConstraint":">=11.0.0,<=11.0.15 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hmr7-m48g-48f6","fix":{"state":"fixed","versions":["11.0.16"],"available":[{"date":"2023-09-15","kind":"first-observed","version":"11.0.16"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-40167","cwe":"CWE-130","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-40167","date":"2026-10-08","epss":0.01279,"percentile":0.69122}],"risk":0.658685,"urls":["https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6","https://www.rfc-editor.org/rfc/rfc9110#section-8.6","https://nvd.nist.gov/vuln/detail/CVE-2023-40167","https://www.debian.org/security/2023/dsa-5507","https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hmr7-m48g-48f6","description":"Jetty accepts \"+\" prefixed value in Content-Length"},"relatedVulnerabilities":[{"id":"CVE-2023-40167","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2023-40167","cwe":"CWE-130","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2023-40167","date":"2026-10-08","epss":0.01279,"percentile":0.69122}],"urls":["https://github.com/eclipse/jetty.project/security/advisories/GHSA-hmr7-m48g-48f6","https://lists.debian.org/debian-lts-announce/2023/09/msg00039.html","https://www.debian.org/security/2023/dsa-5507","https://www.rfc-editor.org/rfc/rfc9110#section-8.6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2023-40167","description":"Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field.  This is more permissive than allowed by the RFC and other servers routinely reject such requests with 400 responses.  There is no known exploit scenario, but it is conceivable that request smuggling could result if jetty is used in combination with a server that does not close the connection after sending such a 400 response. Versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1 contain a patch for this issue. There is no workaround as there is no known exploit scenario."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-11856","versionConstraint":">= 7.10.6, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-11856","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-11856","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-11856","date":"2026-10-08","epss":0.00688,"percentile":0.51225}],"risk":0.6467200000000001,"urls":["https://curl.se/docs/CVE-2026-11856.html","https://curl.se/docs/CVE-2026-11856.json","https://hackerone.com/reports/3793260"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11856","description":"Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8924","versionConstraint":">= 7.46.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8924","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8924","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8924","date":"2026-10-08","epss":0.00661,"percentile":0.50067}],"risk":0.5982050000000001,"urls":["https://curl.se/docs/CVE-2026-8924.html","https://curl.se/docs/CVE-2026-8924.json","https://hackerone.com/reports/3733905"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8924","description":"A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-10536","versionConstraint":">= 7.88.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-10536","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-10536","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-10536","date":"2026-10-08","epss":0.00598,"percentile":0.46964}],"risk":0.5621200000000001,"urls":["https://curl.se/docs/CVE-2026-10536.html","https://curl.se/docs/CVE-2026-10536.json","https://hackerone.com/reports/3751697"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10536","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation."},"relatedVulnerabilities":[]},{"artifact":{"id":"28649ac0a0f8ba59","cpes":["cpe:2.3:a:org.eclipse.jetty.server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-server","purl":"pkg:maven/org.eclipse.jetty/jetty-server@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-server-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-server","archiveDigests":[{"value":"ce2fc063638c702f2df749dd23cde6c41c7b0c06","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-server-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"11.0.24"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-g8m5-722r-8whq","versionConstraint":">=11.0.0,<=11.0.23 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-server","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-g8m5-722r-8whq","fix":{"state":"fixed","versions":["11.0.24"],"available":[{"date":"2024-10-15","kind":"first-observed","version":"11.0.24"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-8184","cwe":"CWE-400","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-8184","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-8184","date":"2026-10-08","epss":0.0103,"percentile":0.62628}],"risk":0.56135,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-g8m5-722r-8whq","https://nvd.nist.gov/vuln/detail/CVE-2024-8184","https://github.com/jetty/jetty.project/pull/11723","https://gitlab.eclipse.org/security/cve-assignement/-/issues/30","https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-g8m5-722r-8whq","description":"Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks"},"relatedVulnerabilities":[{"id":"CVE-2024-8184","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-8184","cwe":"CWE-400","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-8184","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-8184","date":"2026-10-08","epss":0.0103,"percentile":0.62628}],"urls":["https://github.com/jetty/jetty.project/pull/11723","https://github.com/jetty/jetty.project/security/advisories/GHSA-g8m5-722r-8whq","https://gitlab.eclipse.org/security/cve-assignement/-/issues/30","https://lists.debian.org/debian-lts-announce/2025/04/msg00001.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-8184","description":"There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack.  By repeatedly sending crafted requests, attackers can trigger OutofMemory errors and exhaust the server's memory."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9079","versionConstraint":">= 8.8.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9079","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":9.8,"impactScore":5.9,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9079","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9079","date":"2026-10-08","epss":0.00584,"percentile":0.46211}],"risk":0.54896,"urls":["https://curl.se/docs/CVE-2026-9079.html","https://curl.se/docs/CVE-2026-9079.json","https://hackerone.com/reports/3750295"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9079","description":"libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-18924","versionConstraint":">= 7.44.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-18924","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-18924","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18924","date":"2026-10-08","epss":0.00584,"percentile":0.46233}],"risk":0.52852,"urls":["https://curl.se/docs/CVE-2026-18924.html","https://curl.se/docs/CVE-2026-18924.json","https://hackerone.com/reports/3916059"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18924","description":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-5773","versionConstraint":">= 7.40.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-5773","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-5773","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-5773","cwe":"CWE-918","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-5773","date":"2026-10-08","epss":0.00657,"percentile":0.49896}],"risk":0.49275,"urls":["https://curl.se/docs/CVE-2026-5773.html","https://curl.se/docs/CVE-2026-5773.json","https://hackerone.com/reports/3650689","http://www.openwall.com/lists/oss-security/2026/04/29/9"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-5773","description":"libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same."},"relatedVulnerabilities":[]},{"artifact":{"id":"ef6ba7fd852d826b","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:http:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"06eb099ce51496de87ecfe9b8c62c2e8f3f5e848","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"12.0.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qh8g-58pp-2wxh","versionConstraint":">=7.0.0,<=12.0.11 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qh8g-58pp-2wxh","fix":{"state":"fixed","versions":["12.0.12"],"available":[{"date":"2024-10-15","kind":"first-observed","version":"12.0.12"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6763","date":"2026-10-08","epss":0.00965,"percentile":0.60529}],"risk":0.48250000000000004,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://nvd.nist.gov/vuln/detail/CVE-2024-6763","https://github.com/jetty/jetty.project/pull/12012","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qh8g-58pp-2wxh","description":"Eclipse Jetty URI parsing of invalid authority"},"relatedVulnerabilities":[{"id":"CVE-2024-6763","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-6763","cwe":"CWE-1286","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-6763","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2024-6763","date":"2026-10-08","epss":0.00965,"percentile":0.60529}],"urls":["https://github.com/jetty/jetty.project/pull/12012","https://github.com/jetty/jetty.project/security/advisories/GHSA-qh8g-58pp-2wxh","https://gitlab.eclipse.org/security/cve-assignement/-/issues/25","https://security.netapp.com/advisory/ntap-20250306-0005/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-6763","description":"Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing.\n\nThe HttpURI class does insufficient validation on the authority segment of a URI.  However the behaviour of HttpURI\n differs from the common browsers in how it handles a URI that would be \nconsidered invalid if fully validated against the RRC.  Specifically HttpURI\n and the browser may differ on the value of the host extracted from an \ninvalid URI and thus a combination of Jetty and a vulnerable browser may\n be vulnerable to a open redirect attack or to a SSRF attack if the URI \nis used after passing validation checks."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8927","versionConstraint":">= 7.12.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8927","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8927","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8927","date":"2026-10-08","epss":0.005,"percentile":0.40945}],"risk":0.4525,"urls":["https://curl.se/docs/CVE-2026-8927.html","https://curl.se/docs/CVE-2026-8927.json","https://hackerone.com/reports/3744543"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8927","description":"When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`."},"relatedVulnerabilities":[]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4xh-88c3-wmh7","versionConstraint":">=2.14.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-q4xh-88c3-wmh7","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"risk":0.43575,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7","https://nvd.nist.gov/vuln/detail/CVE-2026-68497","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4xh-88c3-wmh7","description":"jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-68497","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68497","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-68497","cwe":"CWE-1333","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68497","date":"2026-10-08","epss":0.00581,"percentile":0.46036}],"urls":["https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd","https://github.com/FasterXML/jackson-databind/pull/6127","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68497","description":"jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These deserializers are registered by default with no opt-in, so a plain ObjectMapper or JsonMapper with no polymorphic typing and no special configuration reaches this path. The XML Schema lexical grammar permits numeric components of arbitrary length, which the JDK materializes through the native BigInteger(String) and BigDecimal(String) constructors, both quadratic in digit count. Because the digits sit inside a JSON string token rather than a JSON number token, jackson-core's StreamReadConstraints.maxNumberLength guard never applies; jackson's own NumberDeserializers call validateIntegerLength or validateFPLength before parsing a stringified number, but the XML datatype deserializer omits that pre-check. An unauthenticated attacker can therefore submit a single request of a few megabytes, such as a Duration value consisting of the letter P followed by several million digits and the letter Y, and force tens of seconds to several minutes of single-threaded CPU work; a handful of concurrent requests can saturate a server's worker threads. This affects com.fasterxml.jackson.core:jackson-databind from 2.0.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80229","versionConstraint":">= 8.14.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80229","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80229","cwe":"CWE-416","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80229","date":"2026-10-08","epss":0.00563,"percentile":0.45051}],"risk":0.42224999999999996,"urls":["https://curl.se/docs/CVE-2026-80229.html","https://curl.se/docs/CVE-2026-80229.json","https://hackerone.com/reports/3969255"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80229","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations."},"relatedVulnerabilities":[]},{"artifact":{"id":"84734ecc72f4f871","cpes":["cpe:2.3:a:com.github.junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:org.sonatype.oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:github:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*"],"name":"junrar","purl":"pkg:maven/com.github.junrar/junrar@3.0.1-Ubooquity","type":"java-archive","version":"3.0.1-Ubooquity","language":"java","licenses":["UnRar License"],"metadata":{"pomGroupID":"com.github.junrar","virtualPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","manifestName":"","pomArtifactID":"junrar","archiveDigests":[{"value":"1723f2e3c340f769902fa5bb4620d16155ab7314","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"7.5.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j273-m5qq-6825","versionConstraint":"<7.5.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.github.junrar:junrar","version":"3.0.1-Ubooquity"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-j273-m5qq-6825","fix":{"state":"fixed","versions":["7.5.8"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"7.5.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28208","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28208","date":"2026-10-08","epss":0.00754,"percentile":0.53686}],"risk":0.4109300000000001,"urls":["https://github.com/junrar/junrar/security/advisories/GHSA-j273-m5qq-6825","https://nvd.nist.gov/vuln/detail/CVE-2026-28208","https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954","https://github.com/junrar/junrar/releases/tag/v7.5.8"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j273-m5qq-6825","description":"Junrar has an arbitrary file write due to backslash Path Traversal bypass in LocalFolderExtractor on Linux/Unix"},"relatedVulnerabilities":[{"id":"CVE-2026-28208","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-28208","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-28208","date":"2026-10-08","epss":0.00754,"percentile":0.53686}],"urls":["https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954","https://github.com/junrar/junrar/releases/tag/v7.5.8","https://github.com/junrar/junrar/security/advisories/GHSA-j273-m5qq-6825"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-28208","description":"Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often lead to remote code execution (e.g., overwriting shell profiles, source code, cron jobs, etc). Version 7.5.8 has a fix for the issue."}]},{"artifact":{"id":"c9fad4cc848e2840","cpes":["cpe:2.3:a:jonathan-hedley:jsoup:1.16.1:*:*:*:*:*:*:*","cpe:2.3:a:jonathan_hedley:jsoup:1.16.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jsoup:jsoup:1.16.1:*:*:*:*:*:*:*","cpe:2.3:a:jsoup:jsoup:1.16.1:*:*:*:*:*:*:*"],"name":"jsoup","purl":"pkg:maven/org.jsoup/jsoup@1.16.1","type":"java-archive","version":"1.16.1","language":"java","licenses":["https://jsoup.org/license"],"metadata":{"pomGroupID":"org.jsoup","virtualPath":"/app/ubooquity/Ubooquity.jar:jsoup-1.16.1.jar","manifestName":"","pomArtifactID":"jsoup","archiveDigests":[{"value":"ae551410a16433984cd4a8603622fafa9d8299f0","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jsoup-1.16.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-65r4-943x-97jj","versionConstraint":"<1.23.2 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jsoup:jsoup","version":"1.16.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-65r4-943x-97jj","fix":{"state":"fixed","versions":["1.23.2"],"available":[{"date":"2026-10-06","kind":"first-observed","version":"1.23.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75140","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-75140","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"risk":0.40950000000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-75140","https://github.com/jhy/jsoup/pull/2556","https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder","https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.2"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-65r4-943x-97jj","description":"jsoup XmlTreeBuilder vulnerable to memory exhaustion through deeply nested namespace declarations"},"relatedVulnerabilities":[{"id":"CVE-2026-75140","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-75140","cwe":"CWE-770","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-75140","date":"2026-10-08","epss":0.00525,"percentile":0.42712}],"urls":["https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a","https://github.com/jhy/jsoup/pull/2556","https://www.vulncheck.com/advisories/jsoup-uncontrolled-resource-consumption-in-xmltreebuilder"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-75140","description":"jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6253","versionConstraint":">= 7.14.1, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6253","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6253","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6253","date":"2026-10-08","epss":0.0075,"percentile":0.53553}],"risk":0.40875,"urls":["https://curl.se/docs/CVE-2026-6253.html","https://curl.se/docs/CVE-2026-6253.json","https://hackerone.com/reports/3669637","http://www.openwall.com/lists/oss-security/2026/04/29/11"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6253","description":"curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy"},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8926","versionConstraint":">= 8.11.1, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8926","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8926","cwe":"CWE-522","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8926","date":"2026-10-08","epss":0.00444,"percentile":0.36553}],"risk":0.40182000000000007,"urls":["https://curl.se/docs/CVE-2026-8926.html","https://curl.se/docs/CVE-2026-8926.json","https://hackerone.com/reports/3735184"],"severity":"Critical","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8926","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user."},"relatedVulnerabilities":[]},{"artifact":{"id":"2c03804059702481","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.78.1","type":"java-archive","version":"1.78.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"39e9e45359e20998eb79c1828751f94a818d25f8","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.85"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9pwp-9qqc-pr26","versionConstraint":"<1.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.78.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9pwp-9qqc-pr26","fix":{"state":"fixed","versions":["1.85"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"1.85"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8763","cwe":"CWE-295","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-8763","date":"2026-10-08","epss":0.0043,"percentile":0.35225}],"risk":0.3913,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-8763","https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE-2026-8763","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763","https://github.com/bcgit/bc-java/releases/tag/r1rv85v2"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9pwp-9qqc-pr26","description":"Bouncy Castle: Name Constraints bypass via trailing dot in rfc822Name and URI"},"relatedVulnerabilities":[{"id":"CVE-2026-8763","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8763","cwe":"CWE-295","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-8763","date":"2026-10-08","epss":0.0043,"percentile":0.35225}],"urls":["https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8763","description":"In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14819","versionConstraint":">= 7.87.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14819","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14819","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-14819","date":"2026-10-08","epss":0.00756,"percentile":0.53758}],"risk":0.38934,"urls":["https://curl.se/docs/CVE-2025-14819.html","https://curl.se/docs/CVE-2025-14819.json","http://www.openwall.com/lists/oss-security/2026/01/07/5"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14819","description":"When doing TLS related transfers with reused easy or multi handles and\naltering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not."},"relatedVulnerabilities":[]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-gx83-3vf8-gh7j","versionConstraint":">=2.11.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-gx83-3vf8-gh7j","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"risk":0.38001,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j","https://nvd.nist.gov/vuln/detail/CVE-2026-83557","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-gx83-3vf8-gh7j","description":"jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)"},"relatedVulnerabilities":[{"id":"CVE-2026-83557","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.4,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-83557","cwe":"CWE-502","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-83557","cwe":"CWE-915","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-83557","date":"2026-10-08","epss":0.00717,"percentile":0.52375}],"urls":["https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f","https://github.com/FasterXML/jackson-databind/issues/6156","https://github.com/FasterXML/jackson-databind/pull/6155","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-gx83-3vf8-gh7j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-83557","description":"DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of \"unsafe base types\", and its isSafeSubType method returns true unconditionally for every base type outside that set. java.lang.Comparable was absent from the list despite being implemented by a very large fraction of JDK and application classes, comparable in breadth to java.io.Serializable, which is on the list for that reason. An application declaring an @JsonTypeInfo-annotated property or class with Comparable as its base type, and no custom PolymorphicTypeValidator, will accept a type identifier for essentially any class implementing Comparable. This yields an attacker-controlled object instantiation primitive; a demonstrated case constructs a java.io.File for an arbitrary attacker-chosen path, which becomes path-traversal-adjacent if the application subsequently calls path-sensitive methods on the value. No class implementing Comparable has been identified that yields code execution through deserialization alone. Global Default Typing via activateDefaultTyping is not affected, because that method structurally requires an explicit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9547","versionConstraint":">= 7.69.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9547","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9547","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9547","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9547","date":"2026-10-08","epss":0.00508,"percentile":0.41397}],"risk":0.37846,"urls":["https://curl.se/docs/CVE-2026-9547.html","https://curl.se/docs/CVE-2026-9547.json","https://hackerone.com/reports/3751712"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9547","description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack."},"relatedVulnerabilities":[]},{"artifact":{"id":"cfa23a85d6801d53","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-core-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"a6fe1836469a69b3ff66037c324d75fc66ef137c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-core-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-r7wm-3cxj-wff9","versionConstraint":"<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-r7wm-3cxj-wff9","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"risk":0.3750299999999999,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://nvd.nist.gov/vuln/detail/CVE-2026-68494"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-r7wm-3cxj-wff9","description":"jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)"},"relatedVulnerabilities":[{"id":"CVE-2026-68494","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-68494","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-68494","date":"2026-10-08","epss":0.00463,"percentile":0.38164}],"urls":["https://github.com/FasterXML/jackson-core/commit/050b429804dce2a7e08f0be1b0b4c3d040fdb9cd","https://github.com/FasterXML/jackson-core/commit/4cdd529749da396cc7edf6d4a2aad41d47902641","https://github.com/FasterXML/jackson-core/commit/c5941e5aae7fd5aeac55d66933cfb82b9aabeef8","https://github.com/FasterXML/jackson-core/pull/1611","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-r7wm-3cxj-wff9","https://github.com/advisories/GHSA-72hv-8253-57qq","https://www.cve.org/CVERecord?id=CVE-2026-18401"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-68494","description":"The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the remaining bypass.\n\nThe earlier fix wired validateIntegerLength() into a new _setIntLength() helper and invoked it wherever the integer portion of a number is decided: a terminator byte arrives, a '.' or 'e'/'E' is seen, or input ends inside a fully buffered value. It was not invoked on the attacker-relevant path where the parser runs out of input while still inside the MINOR_NUMBER_INTEGER_DIGITS minor state and returns NOT_AVAILABLE to the caller.\n\nAs a result, an attacker who streams JSON to a non-blocking parser in many small chunks, without ever sending a terminator byte, keeps the parser inside MINOR_NUMBER_INTEGER_DIGITS indefinitely. _textBuffer.expandCurrentSegment() grows the accumulator on every chunk while validateIntegerLength() is never called. The accumulator is bounded only by maxStringLength (20 MiB by default) rather than by maxNumberLength (1000 by default), an amplification of roughly 20,000x over the documented limit. Because Java char values occupy two bytes, a single connection can be driven to approximately 40 MiB of heap before the validator finally fires when the value completes.\n\nThe equivalent fraction-path code is correct: _finishFloatFraction() calls _setFractLength() before its NOT_AVAILABLE return. The missing call affects the integer-digit paths in _startPositiveNumber(), _startNegativeNumber() and _finishNumberIntegralPart() in NonBlockingUtf8JsonParserBase.\n\nImpact: reactive frameworks such as Spring WebFlux/Reactor, Quarkus, Helidon and Vert.x feed inbound HTTP or gRPC bytes to the async parser as they arrive, which is precisely the chunked-feed shape required. Operators who set StreamReadConstraints.maxNumberLength expecting it to cap memory per number value do not get that guarantee; memory accumulates per concurrent connection and attacker-controlled concurrency can exhaust the JVM heap. The synchronous parsers (UTF8StreamJsonParser, ReaderBasedJsonParser) and the async parser operating on complete input are not affected.\n\nExploitation requires only the ability to stream data to a parsing endpoint; no privileges or user interaction are needed.\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.7, and from 2.19.0 through 2.21.3, and tools.jackson.core:jackson-core from 3.0.0 through 3.1.3. Versions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-r7wm-3cxj-wff9 states the affected 2.x range without a lower bound. The 2.22.x and 3.2.x release lines are not affected: those branches were created after the fix commit landed on 2026-05-21 and therefore contain it from their initial releases (2.22.0, tagged 2026-06-03, and 3.2.0, tagged 2026-06-08)."}]},{"artifact":{"id":"cfa23a85d6801d53","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-core-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"a6fe1836469a69b3ff66037c324d75fc66ef137c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-core-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7hhh-6rmp-j9qf","versionConstraint":">=2.8.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7hhh-6rmp-j9qf","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-10-01","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"risk":0.369,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf","https://nvd.nist.gov/vuln/detail/CVE-2026-89425","https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-2.18.11","https://github.com/FasterXML/jackson-core/releases/tag/jackson-core-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7hhh-6rmp-j9qf","description":"jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)"},"relatedVulnerabilities":[{"id":"CVE-2026-89425","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89425","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-89425","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-89425","date":"2026-10-08","epss":0.00492,"percentile":0.4033}],"urls":["https://github.com/FasterXML/jackson-core/pull/1698","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89425","description":"UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed token supplied to a parser created through JsonFactory.createParser(DataInput) is therefore accumulated in full. No StreamReadConstraints setting mitigates this: maxDocumentLength cannot be applied to DataInput sources at all, and maxStringLength does not cover this path because the accumulation bypasses ReadConstrainedTextBuffer. The reporter measured a 20,000,109-character exception message from a 20-million-character malformed token on the DataInput path, against 367 characters for identical input on the InputStream path. Scaling the payload drives the StringBuilder, which also incurs byte-to-char expansion and internal array doubling, to many times the raw payload size and can trigger OutOfMemoryError for the whole JVM. UTF8DataInputJsonParser was introduced in 2.8.0 together with createParser(DataInput); releases before 2.8.0 do not contain the affected class."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9080","versionConstraint":">= 8.13.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9080","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":7.3,"impactScore":3.4,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-9080","cwe":"CWE-416","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-9080","date":"2026-10-08","epss":0.00494,"percentile":0.40474}],"risk":0.36556,"urls":["https://curl.se/docs/CVE-2026-9080.html","https://curl.se/docs/CVE-2026-9080.json","https://hackerone.com/reports/3749204"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9080","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80255","versionConstraint":">= 8.14.0, <= 8.14.2||>= 8.16.0, <= 8.16.1||>= 8.20.0, < 8.20.1||>= 8.31.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80255","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80255","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80255","date":"2026-10-08","epss":0.00478,"percentile":0.39331}],"risk":0.35850000000000004,"urls":["https://curl.se/docs/CVE-2026-80255.html","https://curl.se/docs/CVE-2026-80255.json","https://hackerone.com/reports/3972395"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80255","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-13608","versionConstraint":">= 7.82.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-13608","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-13608","cwe":"CWE-923","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-13608","date":"2026-10-08","epss":0.00479,"percentile":0.39377}],"risk":0.356855,"urls":["https://curl.se/docs/CVE-2026-13608.html","https://curl.se/docs/CVE-2026-13608.json","https://hackerone.com/reports/3822248"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13608","description":"A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14524","versionConstraint":">= 7.33.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14524","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14524","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14524","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14524","date":"2026-10-08","epss":0.0068,"percentile":0.50927}],"risk":0.3502,"urls":["https://curl.se/docs/CVE-2025-14524.html","https://curl.se/docs/CVE-2025-14524.json","https://hackerone.com/reports/3459417","http://www.openwall.com/lists/oss-security/2026/01/07/4"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14524","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host."},"relatedVulnerabilities":[]},{"artifact":{"id":"2c03804059702481","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.78.1","type":"java-archive","version":"1.78.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"39e9e45359e20998eb79c1828751f94a818d25f8","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.85"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qp49-qgx5-5m26","versionConstraint":"<1.85 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.78.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qp49-qgx5-5m26","fix":{"state":"fixed","versions":["1.85"],"available":[{"date":"2026-09-19","kind":"first-observed","version":"1.85"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/U:Amber","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13506","cwe":"CWE-674","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-13506","date":"2026-10-08","epss":0.00442,"percentile":0.36375}],"risk":0.34476,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-13506","https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qp49-qgx5-5m26","description":"Bouncy Castle: Lazy ASN.1 sequence forcing resets nesting-depth guard"},"relatedVulnerabilities":[{"id":"CVE-2026-13506","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-13506","cwe":"CWE-674","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"}],"epss":[{"cve":"CVE-2026-13506","date":"2026-10-08","epss":0.00442,"percentile":0.36375}],"urls":["https://github.com/bcgit/bc-java/commit/77454da9b3dcaaa2991412d1c3c1a6e1a338ff84","https://github.com/bcgit/bc-java/wiki/CVE-2026-13506"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-13506","description":"In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series)."}]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-cxp5-3px4-pw24","versionConstraint":">=2.5.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-cxp5-3px4-pw24","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24","https://nvd.nist.gov/vuln/detail/CVE-2026-91777","https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/pull/6204","https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-cxp5-3px4-pw24","description":"jackson-databind quadratic forward-reference completion"},"relatedVulnerabilities":[{"id":"CVE-2026-91777","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91777","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91777","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6204","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91777","description":"Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in an identity-enabled collection or map and then defines those same IDs in reverse order, completion performs on the order of N * (N + 1) / 2 identity comparisons, so a shallow document whose size grows linearly causes quadratic CPU work during deserialization. The reporter instrumented equals() calls on the ID class and measured exactly 2,003,000 comparisons at N = 2,000, against zero comparisons in the pending-reference lookup path for an equally sized control in which every reference was already resolved. The input requires no deep nesting and no syntactically unusual JSON. Exploitation requires an application that deserializes attacker-influenced JSON into an identity-enabled collection or map. The fix replaces the repeated linear lookup with a keyed pending-reference structure."}]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wv8q-qhhj-9h54","versionConstraint":">=2.0.0,<=2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wv8q-qhhj-9h54","fix":{"state":"fixed","versions":["2.18.11"],"available":[{"date":"2026-09-30","kind":"first-observed","version":"2.18.11"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"risk":0.33749999999999997,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54","https://nvd.nist.gov/vuln/detail/CVE-2026-91776","https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.11","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.3","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.7","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.3"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wv8q-qhhj-9h54","description":"jackson-databind retains every unknown raw type ID"},"relatedVulnerabilities":[{"id":"CVE-2026-91776","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-91776","cwe":"CWE-400","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-91776","date":"2026-10-08","epss":0.0045,"percentile":0.3713}],"urls":["https://github.com/FasterXML/jackson-databind/issues/6203","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-91776","description":"TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers map. That map has no configurable bound and lives for the lifetime of the type deserializer, so an attacker who can repeatedly supply fresh unknown type IDs causes monotonic memory retention across requests. The reporter observed 10,000 retained entries from 10,000 distinct unknown IDs, against a single entry for a control that repeated one unknown ID the same number of times, isolating attacker-controlled key cardinality from request volume. Exploitation requires an application that enables name-based polymorphism with a defaultImpl or equivalent fallback, accepts attacker-influenced type IDs, and reuses a long-lived ObjectMapper across requests. The fix stops caching fallback resolutions for unrecognized IDs and bounds both the number of cached entries and the length of a cacheable type ID."}]},{"artifact":{"id":"28649ac0a0f8ba59","cpes":["cpe:2.3:a:org.eclipse.jetty.server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-server","purl":"pkg:maven/org.eclipse.jetty/jetty-server@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-server-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-server","archiveDigests":[{"value":"ce2fc063638c702f2df749dd23cde6c41c7b0c06","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-server-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"11.0.23"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9299-c6m4-mjhc","versionConstraint":">=11.0.7,<11.0.23 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-server","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-9299-c6m4-mjhc","fix":{"state":"fixed","versions":["11.0.23"],"available":[{"date":"2026-07-23","kind":"first-observed","version":"11.0.23"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7708","cwe":"CWE-400","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-7708","cwe":"CWE-401","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2024-7708","date":"2026-10-08","epss":0.0044,"percentile":0.3626}],"risk":0.33,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-9299-c6m4-mjhc","https://nvd.nist.gov/vuln/detail/CVE-2024-7708","https://github.com/jetty/jetty.project/pull/12156","https://github.com/jetty/jetty.project/commit/8259eabbc70ae7fc2d525f1e95b43fbdfd2ad097","https://github.com/jetty/jetty.project/releases/tag/jetty-10.0.23","https://github.com/jetty/jetty.project/releases/tag/jetty-11.0.23","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/29"],"severity":"High","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9299-c6m4-mjhc","description":"Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests"},"relatedVulnerabilities":[{"id":"CVE-2024-7708","cvss":[{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-7708","cwe":"CWE-400","type":"Secondary","source":"emo@eclipse.org"},{"cve":"CVE-2024-7708","cwe":"CWE-401","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2024-7708","date":"2026-10-08","epss":0.0044,"percentile":0.3626}],"urls":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/29"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-7708","description":"For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak.\nThis is particularly the case for 100-Continue, but any request where the network is slow can leak."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-9545","versionConstraint":">= 8.11.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-9545","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9545","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-9545","date":"2026-10-08","epss":0.00408,"percentile":0.32973}],"risk":0.30600000000000005,"urls":["https://curl.se/docs/CVE-2026-9545.html","https://curl.se/docs/CVE-2026-9545.json","https://hackerone.com/reports/3752888"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9545","description":"In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-82208","versionConstraint":">= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0||>= 8.9.1, < 8.14.2 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-82208","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82208","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82208","date":"2026-10-08","epss":0.00407,"percentile":0.3292}],"risk":0.30524999999999997,"urls":["https://curl.se/docs/CVE-2026-82208.html","https://curl.se/docs/CVE-2026-82208.json","https://hackerone.com/reports/3973090"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82208","description":"With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-7168","versionConstraint":">= 7.12.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-7168","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-7168","cwe":"CWE-294","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-7168","date":"2026-10-08","epss":0.00591,"percentile":0.46599}],"risk":0.304365,"urls":["https://curl.se/docs/CVE-2026-7168.html","https://curl.se/docs/CVE-2026-7168.json","https://hackerone.com/reports/3697719","http://www.openwall.com/lists/oss-security/2026/04/29/14"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7168","description":"Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12064","versionConstraint":">= 7.81.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-12064","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12064","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-12064","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-12064","date":"2026-10-08","epss":0.00399,"percentile":0.32065}],"risk":0.29924999999999996,"urls":["https://curl.se/docs/CVE-2026-12064.html","https://curl.se/docs/CVE-2026-12064.json","https://hackerone.com/reports/3797526"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064","description":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8932","versionConstraint":">= 7.7, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8932","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8932","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8932","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8932","date":"2026-10-08","epss":0.00396,"percentile":0.31723}],"risk":0.297,"urls":["https://curl.se/docs/CVE-2026-8932.html","https://curl.se/docs/CVE-2026-8932.json","https://hackerone.com/reports/3733910"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8932","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-82209","versionConstraint":">= 7.46.0, < 8.14.2||>= 8.16.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.20.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-82209","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-82209","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-82209","date":"2026-10-08","epss":0.00373,"percentile":0.29191}],"risk":0.292805,"urls":["https://curl.se/docs/CVE-2026-82209.html","https://curl.se/docs/CVE-2026-82209.json","https://hackerone.com/reports/3972385"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`)."},"relatedVulnerabilities":[]},{"artifact":{"id":"84734ecc72f4f871","cpes":["cpe:2.3:a:com.github.junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:org.sonatype.oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:github:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*"],"name":"junrar","purl":"pkg:maven/com.github.junrar/junrar@3.0.1-Ubooquity","type":"java-archive","version":"3.0.1-Ubooquity","language":"java","licenses":["UnRar License"],"metadata":{"pomGroupID":"com.github.junrar","virtualPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","manifestName":"","pomArtifactID":"junrar","archiveDigests":[{"value":"1723f2e3c340f769902fa5bb4620d16155ab7314","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"7.5.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hf5p-q87m-crj7","versionConstraint":"<7.5.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.github.junrar:junrar","version":"3.0.1-Ubooquity"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hf5p-q87m-crj7","fix":{"state":"fixed","versions":["7.5.10"],"available":[{"date":"2026-04-17","kind":"first-observed","version":"7.5.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41245","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41245","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41245","date":"2026-10-08","epss":0.00532,"percentile":0.43184}],"risk":0.28994000000000003,"urls":["https://github.com/junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7","https://nvd.nist.gov/vuln/detail/CVE-2026-41245","https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7","https://github.com/junrar/junrar/releases/tag/v7.5.10"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hf5p-q87m-crj7","description":"Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix"},"relatedVulnerabilities":[{"id":"CVE-2026-41245","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":9.3,"impactScore":5.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41245","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41245","cwe":"CWE-22","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-41245","date":"2026-10-08","epss":0.00532,"percentile":0.43184}],"urls":["https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7","https://github.com/junrar/junrar/releases/tag/v7.5.10","https://github.com/junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7","https://access.redhat.com/security/cve/CVE-2026-41245","https://bugzilla.redhat.com/show_bug.cgi?id=2459769","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41245.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41245","description":"Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15079","versionConstraint":">= 7.58.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15079","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15079","cwe":"CWE-297","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15079","date":"2026-10-08","epss":0.0055,"percentile":0.44258}],"risk":0.28325,"urls":["https://curl.se/docs/CVE-2025-15079.html","https://curl.se/docs/CVE-2025-15079.json","https://hackerone.com/reports/3477116","http://www.openwall.com/lists/oss-security/2026/01/07/6"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15079","description":"When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file."},"relatedVulnerabilities":[]},{"artifact":{"id":"d4217b86f833fe68","cpes":["cpe:2.3:a:zlib:zlib:1.3.2-r0:*:*:*:*:*:*:*"],"name":"zlib","purl":"pkg:apk/alpine/zlib@1.3.2-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.3.2-r0","language":"","licenses":["Zlib"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libz.so.1"},{"path":"/usr/lib/libz.so.1.3.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"zlib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.22"}},{"fix":{"suggestedVersion":"1.3.2-r1"},"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"< 1.3.2-r1 (apk)"},"matcher":"apk-matcher","searchedBy":{"distro":{"type":"alpine","version":"3.22.6"},"package":{"name":"zlib","version":"1.3.2-r0"},"namespace":"alpine:distro:alpine:3.22"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"fixed","versions":["1.3.2-r1"],"available":[{"date":"2026-10-07","kind":"first-observed","version":"1.3.2-r1"}]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.28124,"urls":[],"severity":"High","namespace":"alpine:distro:alpine:3.22","advisories":[],"dataSource":"https://security.alpinelinux.org/vuln/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"2c03804059702481","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.78.1","type":"java-archive","version":"1.78.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"39e9e45359e20998eb79c1828751f94a818d25f8","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.80.2"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-574f-3g2m-x479","versionConstraint":">=1.59,<=1.80.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.78.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-574f-3g2m-x479","fix":{"state":"fixed","versions":["1.80.2"],"available":[{"date":"2026-07-01","kind":"first-observed","version":"1.80.2"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/RE:M/U:Red","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14813","cwe":"CWE-327","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"cve":"CVE-2025-14813","cwe":"CWE-327","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-14813","date":"2026-10-08","epss":0.0032,"percentile":0.22914}],"risk":0.27840000000000004,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-14813","https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3","https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json","https://bugzilla.redhat.com/show_bug.cgi?id=2458640","https://access.redhat.com/security/cve/CVE-2025-14813","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:11720","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:53806","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246"],"severity":"Critical","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-574f-3g2m-x479","description":"Bouncy Castle for Java GOST 28147 CTR mode reuses keystream after 255 blocks"},"relatedVulnerabilities":[{"id":"CVE-2025-14813","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red","metrics":{"baseScore":9.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14813","cwe":"CWE-327","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"cve":"CVE-2025-14813","cwe":"CWE-327","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-14813","date":"2026-10-08","epss":0.0032,"percentile":0.22914}],"urls":["https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3","https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813","https://access.redhat.com/errata/RHSA-2026:11720","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/security/cve/CVE-2025-14813","https://bugzilla.redhat.com/show_bug.cgi?id=2458640","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14813","description":": Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).\n\n This vulnerability is associated with program files G3413CTRBlockCipher.\n\n\n\nThis issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-80230","versionConstraint":">= 7.45.0, < 8.14.2||>= 8.15.0, < 8.16.1||>= 8.17.0, < 8.20.1||>= 8.21.0, < 8.22.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-80230","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-80230","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-80230","date":"2026-10-08","epss":0.00371,"percentile":0.29002}],"risk":0.27825,"urls":["https://curl.se/docs/CVE-2026-80230.html","https://curl.se/docs/CVE-2026-80230.json","https://hackerone.com/reports/3969300"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-80230","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected."},"relatedVulnerabilities":[]},{"artifact":{"id":"2c03804059702481","cpes":["cpe:2.3:a:org.bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:org.bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov-jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov_jdk18on:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bouncycastle:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov-jdk18on:1.78.1:*:*:*:*:*:*:*","cpe:2.3:a:bcprov:bcprov_jdk18on:1.78.1:*:*:*:*:*:*:*"],"name":"bcprov-jdk18on","purl":"pkg:maven/org.bouncycastle/bcprov-jdk18on@1.78.1","type":"java-archive","version":"1.78.1","language":"java","licenses":[],"metadata":{"pomGroupID":"org.bouncycastle","virtualPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","manifestName":"","pomArtifactID":"bcprov-jdk18on","archiveDigests":[{"value":"39e9e45359e20998eb79c1828751f94a818d25f8","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:bcprov-jdk18on-1.78.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.84"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-c3fc-8qff-9hwx","versionConstraint":">=1.74,<1.84 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.bouncycastle:bcprov-jdk18on","version":"1.78.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-c3fc-8qff-9hwx","fix":{"state":"fixed","versions":["1.84"],"available":[{"date":"2026-04-18","kind":"first-observed","version":"1.84"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/RE:M/U:Amber","metrics":{"baseScore":5.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0636","cwe":"CWE-90","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"cve":"CVE-2026-0636","cwe":"CWE-90","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-0636","date":"2026-10-08","epss":0.00527,"percentile":0.42855}],"risk":0.276675,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-0636","https://github.com/bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbde","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-c3fc-8qff-9hwx","description":"Bouncy Castle has an LDAP injection"},"relatedVulnerabilities":[{"id":"CVE-2026-0636","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber","metrics":{"baseScore":5.5},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0636","cwe":"CWE-90","type":"Secondary","source":"91579145-5d7b-4cc5-b925-a0262ff19630"},{"cve":"CVE-2026-0636","cwe":"CWE-90","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-0636","date":"2026-10-08","epss":0.00527,"percentile":0.42855}],"urls":["https://github.com/bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbde","https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636","https://access.redhat.com/errata/RHSA-2026:11720","https://access.redhat.com/errata/RHSA-2026:11721","https://access.redhat.com/errata/RHSA-2026:13631","https://access.redhat.com/errata/RHSA-2026:14272","https://access.redhat.com/errata/RHSA-2026:14276","https://access.redhat.com/errata/RHSA-2026:17668","https://access.redhat.com/errata/RHSA-2026:18054","https://access.redhat.com/errata/RHSA-2026:18055","https://access.redhat.com/errata/RHSA-2026:18059","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:53644","https://access.redhat.com/errata/RHSA-2026:53645","https://access.redhat.com/errata/RHSA-2026:53646","https://access.redhat.com/errata/RHSA-2026:60239","https://access.redhat.com/errata/RHSA-2026:60246","https://access.redhat.com/errata/RHSA-2026:60247","https://access.redhat.com/errata/RHSA-2026:60248","https://access.redhat.com/errata/RHSA-2026:60249","https://access.redhat.com/errata/RHSA-2026:60250","https://access.redhat.com/errata/RHSA-2026:60251","https://access.redhat.com/errata/RHSA-2026:60252","https://access.redhat.com/errata/RHSA-2026:60254","https://access.redhat.com/errata/RHSA-2026:60256","https://access.redhat.com/errata/RHSA-2026:60259","https://access.redhat.com/errata/RHSA-2026:66488","https://access.redhat.com/security/cve/CVE-2026-0636","https://bugzilla.redhat.com/show_bug.cgi?id=2458641","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0636.json"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0636","description":"Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).\n\n This vulnerability is associated with program files LDAPStoreHelper.\n\n\n\nThis issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84."}]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjgm-6hv5-3cvf","versionConstraint":">=2.8.0,<2.18.10 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjgm-6hv5-3cvf","fix":{"state":"fixed","versions":["2.18.10"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.10"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"risk":0.27243500000000004,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf","https://nvd.nist.gov/vuln/detail/CVE-2026-19032","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.10","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.2","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.6","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.2"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjgm-6hv5-3cvf","description":"jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution"},"relatedVulnerabilities":[{"id":"CVE-2026-19032","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19032","cwe":"CWE-470","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"},{"cve":"CVE-2026-19032","cwe":"CWE-610","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-19032","date":"2026-10-08","epss":0.00529,"percentile":0.42947}],"urls":["https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551","https://github.com/FasterXML/jackson-databind/commit/ce26eda3481cd796f76ba4c53ffe1da23b53f166","https://github.com/FasterXML/jackson-databind/commit/d94bb632becfe0ba96926b9909ab06d1f87aad6d","https://github.com/FasterXML/jackson-databind/pull/6129","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19032","description":"jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the code enumerates ServiceLoader<FileSystemProvider> and calls provider.getPath(uri) on the first provider whose scheme matches the attacker-chosen scheme. Untrusted JSON can therefore select and drive an arbitrary registered FileSystemProvider during readValue under a default JsonMapper, and forces provider class loading at the same time. With only the JDK built-in providers (file, jar/zipfs) present, the resolved path is inert and no mount or network I/O occurs; further impact requires a side-effecting third-party FileSystemProvider on the classpath. This affects com.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.file.Path from untrusted JSON should be avoided regardless of version."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3783","versionConstraint":">= 7.33.0, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3783","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3783","cwe":"CWE-522","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3783","date":"2026-10-08","epss":0.00525,"percentile":0.42692}],"risk":0.27037500000000003,"urls":["https://curl.se/docs/CVE-2026-3783.html","https://curl.se/docs/CVE-2026-3783.json","https://hackerone.com/reports/3583983","http://www.openwall.com/lists/oss-security/2026/03/11/2"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3783","description":"When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-3784","versionConstraint":">= 7.7, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-3784","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-3784","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3784","date":"2026-10-08","epss":0.00469,"percentile":0.38615}],"risk":0.26967499999999994,"urls":["https://curl.se/docs/CVE-2026-3784.html","https://curl.se/docs/CVE-2026-3784.json","https://hackerone.com/reports/3584903","http://www.openwall.com/lists/oss-security/2026/03/11/3","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3784","description":"curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6429","versionConstraint":">= 7.14.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6429","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6429","cwe":"CWE-200","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-6429","date":"2026-10-08","epss":0.00512,"percentile":0.41775}],"risk":0.26368,"urls":["https://curl.se/docs/CVE-2026-6429.html","https://curl.se/docs/CVE-2026-6429.json","https://hackerone.com/reports/3677759"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6429","description":"When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-6276","versionConstraint":">= 7.71.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-6276","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6276","cwe":"CWE-346","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-6276","cwe":"CWE-319","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-6276","date":"2026-10-08","epss":0.00349,"percentile":0.26447}],"risk":0.26175,"urls":["https://curl.se/docs/CVE-2026-6276.html","https://curl.se/docs/CVE-2026-6276.json","https://hackerone.com/reports/3671818","http://www.openwall.com/lists/oss-security/2026/04/29/13"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276","description":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them."},"relatedVulnerabilities":[]},{"artifact":{"id":"c0144d0bb00d6450","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback_core:1.5.6:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.6","type":"java-archive","version":"1.5.6","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"41cbe874701200c5624c19e0ab50d1b88dfcc77d","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pr98-23f8-jwxv","versionConstraint":">=1.4.0,<1.5.13 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-pr98-23f8-jwxv","fix":{"state":"fixed","versions":["1.5.13"],"available":[{"date":"2024-12-21","kind":"first-observed","version":"1.5.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/RE:L/U:Clear","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12798","cwe":"CWE-917","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12798","date":"2026-10-08","epss":0.00458,"percentile":0.37702}],"risk":0.24961000000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-12798","https://logback.qos.ch/news.html#1.5.13","https://github.com/qos-ch/logback/commit/2cb6d520df7592ef1c3a198f1b5df3c10c93e183","https://logback.qos.ch/news.html#1.3.15"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pr98-23f8-jwxv","description":"QOS.CH logback-core Expression Language Injection vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-12798","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Clear","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12798","cwe":"CWE-917","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12798","date":"2026-10-08","epss":0.00458,"percentile":0.37702}],"urls":["https://logback.qos.ch/news.html#1.3.15","https://logback.qos.ch/news.html#1.5.13"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12798","description":"ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core\n      upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows\n      attacker to execute arbitrary code by compromising an existing\n      logback configuration file or by injecting an environment variable\n      before program execution.\n\n\n\n\n\nMalicious logback configuration files can allow the attacker to execute \narbitrary code using the JaninoEventEvaluator extension.\n\n\n\nA successful attack requires the user to have write access to a \nconfiguration file. Alternatively, the attacker could inject a malicious \nenvironment variable pointing to a malicious configuration file. In both \ncases, the attack requires existing privilege."}]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-3pjw-73gf-8qr5","versionConstraint":">=2.15.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-3pjw-73gf-8qr5","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-07-22","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"risk":0.243225,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5","https://nvd.nist.gov/vuln/detail/CVE-2026-59888","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-3pjw-73gf-8qr5","description":"jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy"},"relatedVulnerabilities":[{"id":"CVE-2026-59888","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59888","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59888","date":"2026-10-08","epss":0.00423,"percentile":0.34624}],"urls":["https://github.com/FasterXML/jackson-databind/commit/baa2cdf5ca2b2717fbb88d91955d69d8651df3e4","https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d","https://github.com/FasterXML/jackson-databind/pull/5974","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-3pjw-73gf-8qr5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59888","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"cfa23a85d6801d53","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_core:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:core:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:core:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-core","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-core@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-core-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-core","archiveDigests":[{"value":"a6fe1836469a69b3ff66037c324d75fc66ef137c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-core-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.6"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-72hv-8253-57qq","versionConstraint":">=2.15.0,<=2.18.5 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-core","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-72hv-8253-57qq","fix":{"state":"fixed","versions":["2.18.6"],"available":[{"date":"2026-02-28","kind":"first-observed","version":"2.18.6"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"risk":0.24276000000000003,"urls":["https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://nvd.nist.gov/vuln/detail/CVE-2026-18401"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-72hv-8253-57qq","description":"jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition"},"relatedVulnerabilities":[{"id":"CVE-2026-18401","cvss":[{"type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18401","cwe":"CWE-770","type":"Secondary","source":"36c7be3b-2937-45df-85ea-ca7133ea542c"}],"epss":[{"cve":"CVE-2026-18401","date":"2026-10-08","epss":0.00408,"percentile":0.32972}],"urls":["https://github.com/FasterXML/jackson-core/commit/b0c428e6f993e1b5ece5c1c3cb2523e887cd52cf","https://github.com/FasterXML/jackson-core/pull/1555","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18401","description":"The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON to an application that uses the async parser API can supply a number token of arbitrary length, leading to excessive memory allocation and potential CPU exhaustion, resulting in a denial of service.\n\n\n\nThe synchronous parser enforces this limit correctly, so the constraint is applied inconsistently depending on which parsing API the application uses.\n\n\n\nRoot cause: the async parsing path in NonBlockingUtf8JsonParserBase and related classes never invokes the number length validation methods. Number parsing methods such as _finishNumberIntegralPart() accumulate digits into the TextBuffer without any length check, then call _valueComplete() to finalize the token. _valueComplete() does not call resetInt() or resetFloat(), which are the methods in ParserBase where validateIntegerLength() and validateFPLength() are performed. Because that validation step is skipped, maxNumberLength is never enforced on the async code path.\n\n\n\nImpact: an attacker sending a JSON document containing an arbitrarily long number to an application using the async parser (for example a Spring WebFlux or other reactive application) can cause unbounded allocation in the TextBuffer and an OutOfMemoryError. If the application subsequently calls getBigIntegerValue() or getDecimalValue(), the JVM may additionally be tied up in O(n^2) BigInteger parsing, causing CPU-based denial of service.\n\n\n\nNo privileges or user interaction beyond the ability to submit data for parsing are required.\n\n\n\nThis issue affects com.fasterxml.jackson.core:jackson-core from version 2.15.0 through 2.18.5 and from 2.19.0 through 2.21.0, and tools.jackson.core:jackson-core from 3.0.0 through 3.0.x.\n\n\n\nVersions prior to 2.15.0 are not affected, because StreamReadConstraints -- which defines the maxNumberLength setting -- was first introduced in jackson-core 2.15.0, so no such constraint exists to be bypassed in earlier releases. Note that GHSA-72hv-8253-57qq records the lower bound of the affected 2.x range as 2.0.0."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8286","versionConstraint":">= 7.30.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8286","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":8.1,"impactScore":5.2,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-8286","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-8286","date":"2026-10-08","epss":0.00309,"percentile":0.21809}],"risk":0.24101999999999998,"urls":["https://curl.se/docs/CVE-2026-8286.html","https://curl.se/docs/CVE-2026-8286.json","https://hackerone.com/reports/3718195"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8286","description":"A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not."},"relatedVulnerabilities":[]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5jmj-h7xm-6q6v","versionConstraint":">=2.8.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-5jmj-h7xm-6q6v","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"risk":0.228145,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://nvd.nist.gov/vuln/detail/CVE-2026-54515"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5jmj-h7xm-6q6v","description":"jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties"},"relatedVulnerabilities":[{"id":"CVE-2026-54515","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54515","cwe":"CWE-915","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54515","date":"2026-10-08","epss":0.00443,"percentile":0.36467}],"urls":["https://github.com/FasterXML/jackson-databind/commit/0e1b0b211f7a53baa62ba2f4c9bd006c7bf4d5fa","https://github.com/FasterXML/jackson-databind/issues/5962","https://github.com/FasterXML/jackson-databind/issues/5964","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5jmj-h7xm-6q6v"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54515","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-8458","versionConstraint":">= 7.43.0, < 8.21.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-8458","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8458","cwe":"CWE-488","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2026-8458","date":"2026-10-08","epss":0.00371,"percentile":0.29004}],"risk":0.213325,"urls":["https://curl.se/docs/CVE-2026-8458.html","https://curl.se/docs/CVE-2026-8458.json","https://hackerone.com/reports/3721183"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8458","description":"libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services."},"relatedVulnerabilities":[]},{"artifact":{"id":"fd17686e5bed5aa5","cpes":["cpe:2.3:a:coreutils:coreutils:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.7-r1?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/chcon"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/runcon"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"a082454f2af64147","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"684b0dd3c2afb260","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"3c17affff9d77397","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.20115999999999998,"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-10966","versionConstraint":">= 7.69.0, < 8.16.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-10966","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-10966","cwe":"CWE-322","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"}],"epss":[{"cve":"CVE-2025-10966","date":"2026-10-08","epss":0.00427,"percentile":0.34978}],"risk":0.198555,"urls":["https://curl.se/docs/CVE-2025-10966.html","https://curl.se/docs/CVE-2025-10966.json","https://hackerone.com/reports/3355218","http://www.openwall.com/lists/oss-security/2025/11/05/2","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/curl/curl/commit/b011e3fcfb06d6c0278595ee2ee297036fbe9793"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-10966","description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-4873","versionConstraint":">= 7.20.0, < 8.20.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-4873","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-4873","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-4873","cwe":"CWE-319","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-4873","date":"2026-10-08","epss":0.00359,"percentile":0.27581}],"risk":0.195655,"urls":["https://curl.se/docs/CVE-2026-4873.html","https://curl.se/docs/CVE-2026-4873.json","https://hackerone.com/reports/3621851","http://www.openwall.com/lists/oss-security/2026/04/29/7"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-4873","description":"A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted."},"relatedVulnerabilities":[]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hgj6-7826-r7m5","versionConstraint":">=2.0.0,<2.18.8 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-hgj6-7826-r7m5","fix":{"state":"fixed","versions":["2.18.8"],"available":[{"date":"2026-06-24","kind":"first-observed","version":"2.18.8"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"risk":0.18952000000000002,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://nvd.nist.gov/vuln/detail/CVE-2026-54514"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hgj6-7826-r7m5","description":"jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)"},"relatedVulnerabilities":[{"id":"CVE-2026-54514","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54514","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54514","date":"2026-10-08","epss":0.00368,"percentile":0.2857}],"urls":["https://github.com/FasterXML/jackson-databind/commit/1f5a1037b1e9e05920e755cb35f198bcd46667e4","https://github.com/FasterXML/jackson-databind/pull/5951","https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-hgj6-7826-r7m5"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54514","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4."}]},{"artifact":{"id":"2a3b9c07c7f4cf56","cpes":["cpe:2.3:a:nghttp2-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp-libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp_libs:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp2:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp2_libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp-libs:1.69.0-r0:*:*:*:*:*:*:*","cpe:2.3:a:nghttp:nghttp_libs:1.69.0-r0:*:*:*:*:*:*:*"],"name":"nghttp2-libs","purl":"pkg:apk/alpine/nghttp2-libs@1.69.0-r0?arch=x86_64&distro=alpine-3.22.6&upstream=nghttp2","type":"apk","version":"1.69.0-r0","language":"","licenses":["MIT"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libnghttp2.so.14"},{"path":"/usr/lib/libnghttp2.so.14.29.4"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"nghttp2"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:nghttp2:nghttp2:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-58055","versionConstraint":"<= 1.69.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:nghttp2:nghttp2:1.69.0:*:*:*:*:*:*:*"],"package":{"name":"nghttp2","version":"1.69.0-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-58055","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","metrics":{"baseScore":5.4,"impactScore":2.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-58055","cwe":"CWE-444","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-58055","date":"2026-10-08","epss":0.00319,"percentile":0.22818}],"risk":0.1730575,"urls":["https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc","https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e","https://www.vulncheck.com/advisories/nghttp2-nghttpx-http-request-response-smuggling-via-upgrade-request-with-content-length"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-58055","description":"nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning."},"relatedVulnerabilities":[]},{"artifact":{"id":"196b0b96f9c259d7","cpes":["cpe:2.3:a:busybox:busybox:1.37.0-r20:*:*:*:*:*:*:*"],"name":"busybox","purl":"pkg:apk/alpine/busybox@1.37.0-r20?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.37.0-r20","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/busybox"},{"path":"/etc"},{"path":"/etc/securetty"},{"path":"/etc/busybox-paths.d"},{"path":"/etc/busybox-paths.d/busybox"},{"path":"/etc/logrotate.d"},{"path":"/etc/logrotate.d/acpid"},{"path":"/etc/network"},{"path":"/etc/network/if-down.d"},{"path":"/etc/network/if-post-down.d"},{"path":"/etc/network/if-post-up.d"},{"path":"/etc/network/if-pre-down.d"},{"path":"/etc/network/if-pre-up.d"},{"path":"/etc/network/if-up.d"},{"path":"/etc/network/if-up.d/dad"},{"path":"/etc/udhcpc"},{"path":"/etc/udhcpc/udhcpc.conf"},{"path":"/sbin"},{"path":"/usr"},{"path":"/usr/sbin"},{"path":"/usr/share"},{"path":"/usr/share/udhcpc"},{"path":"/usr/share/udhcpc/default.script"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r20"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"57f6a17b40a606dc","cpes":["cpe:2.3:a:busybox-binsh:busybox-binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox-binsh:busybox_binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox-binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox_binsh:busybox_binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox-binsh:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:busybox:busybox_binsh:1.37.0-r20:*:*:*:*:*:*:*"],"name":"busybox-binsh","purl":"pkg:apk/alpine/busybox-binsh@1.37.0-r20?arch=x86_64&distro=alpine-3.22.6&upstream=busybox","type":"apk","version":"1.37.0-r20","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/sh"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r20"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"749529783a76cce6","cpes":["cpe:2.3:a:ssl-client:ssl-client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl-client:ssl_client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl-client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl_client:ssl_client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl-client:1.37.0-r20:*:*:*:*:*:*:*","cpe:2.3:a:ssl:ssl_client:1.37.0-r20:*:*:*:*:*:*:*"],"name":"ssl_client","purl":"pkg:apk/alpine/ssl_client@1.37.0-r20?arch=x86_64&distro=alpine-3.22.6&upstream=busybox","type":"apk","version":"1.37.0-r20","language":"","licenses":["GPL-2.0-only"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/ssl_client"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"busybox"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-60876","versionConstraint":"<= 1.37.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:busybox:busybox:1.37.0:*:*:*:*:*:*:*"],"package":{"name":"busybox","version":"1.37.0-r20"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-60876","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-60876","cwe":"CWE-284","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-60876","date":"2026-10-08","epss":0.00291,"percentile":0.19874}],"risk":0.16732499999999997,"urls":["https://gist.github.com/subyumatest/41554af6a72aedaacaec026adc311092","https://lists.busybox.net/pipermail/busybox/attachments/20250823/ccdc96ef/attachment-0001.htm","https://lists.busybox.net/pipermail/busybox/attachments/20250828/e7f90492/attachment.htm","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-60876","description":"BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20)."},"relatedVulnerabilities":[]},{"artifact":{"id":"546f6397f0070cc9","cpes":["cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core.jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson.core:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:com.fasterxml.jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson-databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson_databind:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson-databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson_databind:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:fasterxml:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:jackson:jackson:2.15.2:*:*:*:*:*:*:*","cpe:2.3:a:core:jackson:2.15.2:*:*:*:*:*:*:*"],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.15.2","type":"java-archive","version":"2.15.2","language":"java","licenses":["https://www.apache.org/licenses/LICENSE-2.0.txt"],"metadata":{"pomGroupID":"com.fasterxml.jackson.core","virtualPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","manifestName":"","pomArtifactID":"jackson-databind","archiveDigests":[{"value":"9353b021f10c307c00328f52090de2bdb4b6ff9c","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jackson-databind-2.15.2.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"2.18.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vvgp-rfg2-7rr6","versionConstraint":">=2.0.0,<2.18.9 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.fasterxml.jackson.core:jackson-databind","version":"2.15.2"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-vvgp-rfg2-7rr6","fix":{"state":"fixed","versions":["2.18.9"],"available":[{"date":"2026-09-29","kind":"first-observed","version":"2.18.9"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"risk":0.161195,"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6","https://nvd.nist.gov/vuln/detail/CVE-2026-77310","https://github.com/FasterXML/jackson-databind/pull/6058","https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.18.9","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.21.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.22.1","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.1.5","https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-3.2.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vvgp-rfg2-7rr6","description":"jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization"},"relatedVulnerabilities":[{"id":"CVE-2026-77310","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77310","cwe":"CWE-918","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-77310","date":"2026-10-08","epss":0.00313,"percentile":0.22169}],"urls":["https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-vvgp-rfg2-7rr6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77310","description":"jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on attacker-controlled input, causing eager DNS resolution during deserialization and enabling DNS-based server-side request forgery and internal-host enumeration. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1."}]},{"artifact":{"id":"28649ac0a0f8ba59","cpes":["cpe:2.3:a:org.eclipse.jetty.server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:server:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:server:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-server","purl":"pkg:maven/org.eclipse.jetty/jetty-server@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-server-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-server","archiveDigests":[{"value":"ce2fc063638c702f2df749dd23cde6c41c7b0c06","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-server-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-7p3p-8qv8-m2vh","versionConstraint":">=11.0.0,<=11.0.26 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-server","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-7p3p-8qv8-m2vh","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6790","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-6790","date":"2026-10-08","epss":0.0031,"percentile":0.21898}],"risk":0.15965000000000001,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-7p3p-8qv8-m2vh","https://nvd.nist.gov/vuln/detail/CVE-2026-6790","https://github.com/jetty/jetty.project/issues/14870","https://github.com/jetty/jetty.project/pull/14871","https://github.com/jetty/jetty.project/pull/14897","https://github.com/jetty/jetty.project/pull/14970","https://github.com/jetty/jetty.project/commit/3e5a4daec196859b8886b6f67b1157dab47cdb6f","https://github.com/jetty/jetty.project/commit/67ba9e6b39661810123680d9c894e99a7940c73d","https://github.com/jetty/jetty.project/commit/cbca3076f7c914a232e7a8b22fa95fbf7e67a6cc","https://github.com/jetty/jetty.project/releases/tag/jetty-12.0.35","https://github.com/jetty/jetty.project/releases/tag/jetty-12.1.9","https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-7p3p-8qv8-m2vh","description":"Eclipse Jetty: HTTP Authority/Host mismatch"},"relatedVulnerabilities":[{"id":"CVE-2026-6790","cvss":[{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6790","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2026-6790","date":"2026-10-08","epss":0.0031,"percentile":0.21898}],"urls":["https://gitlab.eclipse.org/security/cve-assignment/-/work_items/99"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6790","description":"In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in the Host header (if present).\n\n\n\n\nThis was not enforced in earlier HTTP RFC (for example, in RFC 2616), but it is in the latest RFC (9110 and 9112).\n\n\n\n\nThis mismatch can cause a number of problems that may be classified as vulnerabilities such as:\n\n\n\n  *  \n        \n      URI constructions (for example, for redirects -- this is typical for login pages)\n\n  *  \n        \n      Virtual host selection\n\n  *  \n        \n      Reverse proxying\n\n  *  \n        \n      Misleading logs\n\n  *  \n        \n      Etc.\n\n\n\n\n\n\nGiven that the latest RFCs require that request authority and Host header must match, Jetty should enforce this invariant."}]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-1965","versionConstraint":">= 7.10.6, < 8.19.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-1965","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2026-1965","cwe":"CWE-305","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-1965","date":"2026-10-08","epss":0.00264,"percentile":0.16794}],"risk":0.1518,"urls":["https://curl.se/docs/CVE-2026-1965.html","https://curl.se/docs/CVE-2026-1965.json"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1965","description":"libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API)."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15224","versionConstraint":">= 7.58.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15224","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.1,"impactScore":1.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-15224","cwe":"CWE-287","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-15224","date":"2026-10-08","epss":0.0048,"percentile":0.39438}],"risk":0.14639999999999997,"urls":["https://curl.se/docs/CVE-2025-15224.html","https://curl.se/docs/CVE-2025-15224.json","https://hackerone.com/reports/3480925","http://www.openwall.com/lists/oss-security/2026/01/07/7"],"severity":"Low","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15224","description":"When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent."},"relatedVulnerabilities":[]},{"artifact":{"id":"c9fad4cc848e2840","cpes":["cpe:2.3:a:jonathan-hedley:jsoup:1.16.1:*:*:*:*:*:*:*","cpe:2.3:a:jonathan_hedley:jsoup:1.16.1:*:*:*:*:*:*:*","cpe:2.3:a:org.jsoup:jsoup:1.16.1:*:*:*:*:*:*:*","cpe:2.3:a:jsoup:jsoup:1.16.1:*:*:*:*:*:*:*"],"name":"jsoup","purl":"pkg:maven/org.jsoup/jsoup@1.16.1","type":"java-archive","version":"1.16.1","language":"java","licenses":["https://jsoup.org/license"],"metadata":{"pomGroupID":"org.jsoup","virtualPath":"/app/ubooquity/Ubooquity.jar:jsoup-1.16.1.jar","manifestName":"","pomArtifactID":"jsoup","archiveDigests":[{"value":"ae551410a16433984cd4a8603622fafa9d8299f0","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jsoup-1.16.1.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.23.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-pmhh-3w7g-xqp8","versionConstraint":">=1.14.3,<1.23.1 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.jsoup:jsoup","version":"1.16.1"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-pmhh-3w7g-xqp8","fix":{"state":"fixed","versions":["1.23.1"],"available":[{"date":"2026-08-07","kind":"first-observed","version":"1.23.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.7,"impactScore":2.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71497","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71497","date":"2026-10-08","epss":0.00296,"percentile":0.2037}],"risk":0.14356,"urls":["https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8","https://github.com/jhy/jsoup/issues/2538","https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70","https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.1"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-pmhh-3w7g-xqp8","description":"jsoup: Cleaner may expose markup with custom raw-text elements"},"relatedVulnerabilities":[{"id":"CVE-2026-71497","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.7,"impactScore":2.8,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-71497","cwe":"CWE-79","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-71497","date":"2026-10-08","epss":0.00296,"percentile":0.2037}],"urls":["https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70","https://github.com/jhy/jsoup/issues/2538","https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.1","https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-71497","description":"jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1."}]},{"artifact":{"id":"9f5c7138c38f1915","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.2.14-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56109","versionConstraint":"< 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56109","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.8,"impactScore":4.3,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56109","cwe":"CWE-415","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-56109","date":"2026-10-08","epss":0.00186,"percentile":0.07489}],"risk":0.13392,"urls":["https://github.com/alsa-project/alsa-lib/commit/536dd6f8affdf5197c12a63a71c92a70b2833cc0","https://github.com/alsa-project/alsa-lib/releases/tag/v1.2.16.1","https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-library-double-free-via-parse-def-in-conf-c"],"severity":"High","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56109","description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-13034","versionConstraint":">= 8.8.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-13034","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-13034","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-13034","date":"2026-10-08","epss":0.00239,"percentile":0.13699}],"risk":0.130255,"urls":["https://curl.se/docs/CVE-2025-13034.html","https://curl.se/docs/CVE-2025-13034.json"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-13034","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification."},"relatedVulnerabilities":[]},{"artifact":{"id":"84734ecc72f4f871","cpes":["cpe:2.3:a:com.github.junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:org.sonatype.oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:sonatype:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:github:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:junrar:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*","cpe:2.3:a:oss:junrar:3.0.1-Ubooquity:*:*:*:*:*:*:*"],"name":"junrar","purl":"pkg:maven/com.github.junrar/junrar@3.0.1-Ubooquity","type":"java-archive","version":"3.0.1-Ubooquity","language":"java","licenses":["UnRar License"],"metadata":{"pomGroupID":"com.github.junrar","virtualPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","manifestName":"","pomArtifactID":"junrar","archiveDigests":[{"value":"1723f2e3c340f769902fa5bb4620d16155ab7314","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:junrar-3.0.1-Ubooquity.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"7.6.1"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-89m4-43j5-vhhx","versionConstraint":"<=7.6.0 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"com.github.junrar:junrar","version":"3.0.1-Ubooquity"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-89m4-43j5-vhhx","fix":{"state":"fixed","versions":["7.6.1"],"available":[{"date":"2026-09-18","kind":"first-observed","version":"7.6.1"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86071","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-86071","date":"2026-10-08","epss":0.00362,"percentile":0.28012}],"risk":0.12126999999999999,"urls":["https://github.com/junrar/junrar/security/advisories/GHSA-89m4-43j5-vhhx","https://nvd.nist.gov/vuln/detail/CVE-2026-86071","https://github.com/junrar/junrar/commit/e6e333b195a1e3ad271a18fd79d8ac1eb5289343","https://github.com/junrar/junrar/releases/tag/v7.6.1"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-89m4-43j5-vhhx","description":"Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root"},"relatedVulnerabilities":[{"id":"CVE-2026-86071","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86071","cwe":"CWE-22","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-86071","date":"2026-10-08","epss":0.00362,"percentile":0.28012}],"urls":["https://github.com/junrar/junrar/commit/e6e333b195a1e3ad271a18fd79d8ac1eb5289343","https://github.com/junrar/junrar/releases/tag/v7.6.1","https://github.com/junrar/junrar/security/advisories/GHSA-89m4-43j5-vhhx"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86071","description":"Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a crafted archive entry. LocalFolderExtractor.createFile() validates only the final canonical file path, while LocalFolderExtractor.makeFile() creates intermediate path segments with unchecked mkdir() calls. An entry can therefore make the final path resolve inside the destination while causing intermediate directory creation outside it, enabling filesystem pollution or file-versus-directory squatting that can make later security-sensitive writes fail. The demonstrated impact is directory creation, not unconditional arbitrary file-content write. This issue is fixed in version 7.6.1."}]},{"artifact":{"id":"c0144d0bb00d6450","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback_core:1.5.6:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.6","type":"java-archive","version":"1.5.6","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"41cbe874701200c5624c19e0ab50d1b88dfcc77d","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.33"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-p47f-322f-whfh","versionConstraint":"<=1.5.32 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-p47f-322f-whfh","fix":{"state":"fixed","versions":["1.5.33"],"available":[{"date":"2026-07-02","kind":"first-observed","version":"1.5.33"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:L/U:Green","metrics":{"baseScore":1.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9828","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-9828","date":"2026-10-08","epss":0.00545,"percentile":0.43985}],"risk":0.11445,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-9828","https://logback.qos.ch/news.html#1.5.33"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-p47f-322f-whfh","description":"QOS.CH Sarl logback logback-core has a deserialization of untrusted data vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2026-9828","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:L/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-9828","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-9828","date":"2026-10-08","epss":0.00545,"percentile":0.43985}],"urls":["https://logback.qos.ch/news.html#1.5.33"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-9828","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate objects from\n classes in the java.lang and java.util packages that are not explicitly\n blocked.\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.32 inclusive."}]},{"artifact":{"id":"c0144d0bb00d6450","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback_core:1.5.6:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.6","type":"java-archive","version":"1.5.6","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"41cbe874701200c5624c19e0ab50d1b88dfcc77d","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.34"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jhq6-gfmj-v8fx","versionConstraint":"<1.5.34 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-jhq6-gfmj-v8fx","fix":{"state":"fixed","versions":["1.5.34"],"available":[{"date":"2026-07-16","kind":"first-observed","version":"1.5.34"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/RE:M/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10532","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-10532","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"risk":0.10915,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-10532","https://logback.qos.ch/news.html#1.5.34","https://github.com/qos-ch/logback/releases/tag/v_1.5.34"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jhq6-gfmj-v8fx","description":"Logback vulnerable to Object Injection through HardenedObjectInputStream modules"},"relatedVulnerabilities":[{"id":"CVE-2026-10532","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":2.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-10532","cwe":"CWE-502","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-10532","date":"2026-10-08","epss":0.0037,"percentile":0.28843}],"urls":["https://logback.qos.ch/news.html#1.5.34"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-10532","description":"Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.\n\nMore precisely, an attacker able to influence serialized data sent to \nSimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.\n\n\nAlthough deserialization is heavily restricted by HardenedObjectInputStream and no \npractical way to achieve remote code execution or significant privilege \nescalation has been identified, this issue constitutes a bypass of the \nintended security restrictions.\n\n\n\nThis issue affects logback: through 1.5.33 inclusive."}]},{"artifact":{"id":"c0144d0bb00d6450","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback_core:1.5.6:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.6","type":"java-archive","version":"1.5.6","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"41cbe874701200c5624c19e0ab50d1b88dfcc77d","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.19"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-25qh-j22f-pwp8","versionConstraint":">=1.4.0,<1.5.19 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-25qh-j22f-pwp8","fix":{"state":"fixed","versions":["1.5.19"],"available":[{"date":"2025-10-22","kind":"first-observed","version":"1.5.19"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11226","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2025-11226","date":"2026-10-08","epss":0.00194,"percentile":0.08266}],"risk":0.10573000000000002,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-11226","https://logback.qos.ch/news.html#1.5.19","https://github.com/qos-ch/logback/commit/61f6a2544f36b3016e0efd434ee21f19269f1df7","https://github.com/qos-ch/logback/releases/tag/v_1.5.19","https://github.com/qos-ch/logback/issues/974","https://logback.qos.ch/news.html#1.3.16"],"severity":"Medium","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-25qh-j22f-pwp8","description":"QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processing"},"relatedVulnerabilities":[{"id":"CVE-2025-11226","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11226","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2025-11226","date":"2026-10-08","epss":0.00194,"percentile":0.08266}],"urls":["https://logback.qos.ch/news.html#1.3.16","https://logback.qos.ch/news.html#1.5.19"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11226","description":"ACE vulnerability in conditional configuration file processing  by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.\n\n\n\nA successful attack requires the presence of Janino library and Spring Framework to be present on the user's class path. In addition, the attacker must  have write access to a \nconfiguration file. Alternatively, the attacker could inject a malicious \nenvironment variable pointing to a malicious configuration file. In both \ncases, the attack requires existing privilege."}]},{"artifact":{"id":"fd17686e5bed5aa5","cpes":["cpe:2.3:a:coreutils:coreutils:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:apk/alpine/coreutils@9.7-r1?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/bin"},{"path":"/bin/base64"},{"path":"/bin/cat"},{"path":"/bin/chgrp"},{"path":"/bin/chmod"},{"path":"/bin/chown"},{"path":"/bin/coreutils"},{"path":"/bin/cp"},{"path":"/bin/date"},{"path":"/bin/dd"},{"path":"/bin/df"},{"path":"/bin/echo"},{"path":"/bin/false"},{"path":"/bin/link"},{"path":"/bin/ln"},{"path":"/bin/ls"},{"path":"/bin/mkdir"},{"path":"/bin/mknod"},{"path":"/bin/mktemp"},{"path":"/bin/mv"},{"path":"/bin/nice"},{"path":"/bin/printenv"},{"path":"/bin/pwd"},{"path":"/bin/rm"},{"path":"/bin/rmdir"},{"path":"/bin/sleep"},{"path":"/bin/stat"},{"path":"/bin/stty"},{"path":"/bin/sync"},{"path":"/bin/touch"},{"path":"/bin/true"},{"path":"/bin/uname"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/["},{"path":"/usr/bin/b2sum"},{"path":"/usr/bin/base32"},{"path":"/usr/bin/basename"},{"path":"/usr/bin/basenc"},{"path":"/usr/bin/chcon"},{"path":"/usr/bin/cksum"},{"path":"/usr/bin/comm"},{"path":"/usr/bin/csplit"},{"path":"/usr/bin/cut"},{"path":"/usr/bin/dir"},{"path":"/usr/bin/dircolors"},{"path":"/usr/bin/dirname"},{"path":"/usr/bin/du"},{"path":"/usr/bin/expand"},{"path":"/usr/bin/expr"},{"path":"/usr/bin/factor"},{"path":"/usr/bin/fold"},{"path":"/usr/bin/head"},{"path":"/usr/bin/hostid"},{"path":"/usr/bin/id"},{"path":"/usr/bin/install"},{"path":"/usr/bin/join"},{"path":"/usr/bin/logname"},{"path":"/usr/bin/md5sum"},{"path":"/usr/bin/mkfifo"},{"path":"/usr/bin/nl"},{"path":"/usr/bin/nohup"},{"path":"/usr/bin/nproc"},{"path":"/usr/bin/numfmt"},{"path":"/usr/bin/od"},{"path":"/usr/bin/paste"},{"path":"/usr/bin/pathchk"},{"path":"/usr/bin/pinky"},{"path":"/usr/bin/pr"},{"path":"/usr/bin/printf"},{"path":"/usr/bin/ptx"},{"path":"/usr/bin/readlink"},{"path":"/usr/bin/realpath"},{"path":"/usr/bin/runcon"},{"path":"/usr/bin/seq"},{"path":"/usr/bin/sha1sum"},{"path":"/usr/bin/sha224sum"},{"path":"/usr/bin/sha256sum"},{"path":"/usr/bin/sha384sum"},{"path":"/usr/bin/shred"},{"path":"/usr/bin/shuf"},{"path":"/usr/bin/sort"},{"path":"/usr/bin/split"},{"path":"/usr/bin/stdbuf"},{"path":"/usr/bin/sum"},{"path":"/usr/bin/tac"},{"path":"/usr/bin/tail"},{"path":"/usr/bin/tee"},{"path":"/usr/bin/test"},{"path":"/usr/bin/timeout"},{"path":"/usr/bin/tr"},{"path":"/usr/bin/truncate"},{"path":"/usr/bin/tsort"},{"path":"/usr/bin/tty"},{"path":"/usr/bin/unexpand"},{"path":"/usr/bin/uniq"},{"path":"/usr/bin/unlink"},{"path":"/usr/bin/users"},{"path":"/usr/bin/vdir"},{"path":"/usr/bin/wc"},{"path":"/usr/bin/who"},{"path":"/usr/bin/whoami"},{"path":"/usr/bin/yes"},{"path":"/usr/libexec"},{"path":"/usr/libexec/coreutils"},{"path":"/usr/libexec/coreutils/libstdbuf.so"},{"path":"/usr/sbin"},{"path":"/usr/sbin/chroot"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"a082454f2af64147","cpes":["cpe:2.3:a:coreutils-env:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-env:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_env:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-env:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_env:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-env","purl":"pkg:apk/alpine/coreutils-env@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/env"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"684b0dd3c2afb260","cpes":["cpe:2.3:a:coreutils-fmt:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-fmt:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_fmt:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-fmt:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_fmt:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-fmt","purl":"pkg:apk/alpine/coreutils-fmt@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/fmt"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"3c17affff9d77397","cpes":["cpe:2.3:a:coreutils-sha512sum:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils-sha512sum:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils_sha512sum:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:coreutils:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils-sha512sum:9.7-r1:*:*:*:*:*:*:*","cpe:2.3:a:gnu:coreutils_sha512sum:9.7-r1:*:*:*:*:*:*:*"],"name":"coreutils-sha512sum","purl":"pkg:apk/alpine/coreutils-sha512sum@9.7-r1?arch=x86_64&distro=alpine-3.22.6&upstream=coreutils","type":"apk","version":"9.7-r1","language":"","licenses":["GPL-3.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/sha512sum"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"coreutils"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:gnu:coreutils:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-56391","versionConstraint":">= 9.5, <= 9.11 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:gnu:coreutils:9.7:*:*:*:*:*:*:*"],"package":{"name":"coreutils","version":"9.7-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-56391","fix":{"state":"","versions":[]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56391","cwe":"CWE-125","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56391","date":"2026-10-08","epss":0.00171,"percentile":0.05865}],"risk":0.0884925,"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56391","https://git.savannah.gnu.org/cgit/coreutils.git/","https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56391","description":"GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. \nThis incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.\n\nWhen running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.\n\n\nThis issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371."},"relatedVulnerabilities":[]},{"artifact":{"id":"9f5c7138c38f1915","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.2.14-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-90781","versionConstraint":"<= 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-90781","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-90781","cwe":"CWE-193","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-90781","date":"2026-10-08","epss":0.0017,"percentile":0.0582}],"risk":0.08159999999999999,"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241","https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020","https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-90781","description":"alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process."},"relatedVulnerabilities":[]},{"artifact":{"id":"7fee85dc9f5021cc","cpes":["cpe:2.3:a:freetype:freetype:2.13.3-r0:*:*:*:*:*:*:*"],"name":"freetype","purl":"pkg:apk/alpine/freetype@2.13.3-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"2.13.3-r0","language":"","licenses":["FTL OR GPL-2.0-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/lib"},{"path":"/usr/lib/libfreetype.so.6"},{"path":"/usr/lib/libfreetype.so.6.20.2"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"freetype"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:freetype:freetype:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-23865","versionConstraint":">= 2.13.2, <= 2.13.3||>= 2.14.0, <= 2.14.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:freetype:freetype:2.13.3:*:*:*:*:*:*:*"],"package":{"name":"freetype","version":"2.13.3-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-23865","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"cve-assign@fb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","metrics":{"baseScore":5.3,"impactScore":3.4,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-23865","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-23865","date":"2026-10-08","epss":0.00144,"percentile":0.03165}],"risk":0.07416,"urls":["https://gitlab.com/freetype/freetype/-/commit/fc85a255849229c024c8e65f536fe1875d84841c","https://sourceforge.net/projects/freetype/files/freetype2/2.14.2/","https://www.facebook.com/security/advisories/cve-2026-23865","http://www.openwall.com/lists/oss-security/2026/03/03/8"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-23865","description":"An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2."},"relatedVulnerabilities":[]},{"artifact":{"id":"7d2b599b67a6b7e4","cpes":["cpe:2.3:a:curl:curl:8.14.1-r3:*:*:*:*:*:*:*","cpe:2.3:a:haxx:curl:8.14.1-r3:*:*:*:*:*:*:*"],"name":"curl","purl":"pkg:apk/alpine/curl@8.14.1-r3?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"8.14.1-r3","language":"","licenses":["curl"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/curl"},{"path":"/usr/bin/wcurl"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"curl"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-14017","versionConstraint":">= 7.17.0, < 8.18.0 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:haxx:curl:8.14.1:*:*:*:*:*:*:*"],"package":{"name":"curl","version":"8.14.1-r3"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-14017","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-14017","cwe":"CWE-567","type":"Secondary","source":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"cve":"CVE-2025-14017","cwe":"NVD-CWE-Other","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-14017","date":"2026-10-08","epss":0.00114,"percentile":0.01374}],"risk":0.06441,"urls":["https://curl.se/docs/CVE-2025-14017.html","https://curl.se/docs/CVE-2025-14017.json","http://www.openwall.com/lists/oss-security/2026/01/07/3"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-14017","description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well."},"relatedVulnerabilities":[]},{"artifact":{"id":"c0144d0bb00d6450","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback_core:1.5.6:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.6","type":"java-archive","version":"1.5.6","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"41cbe874701200c5624c19e0ab50d1b88dfcc77d","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-6v67-2wr5-gvf4","versionConstraint":">=1.4.0,<1.5.13 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-6v67-2wr5-gvf4","fix":{"state":"fixed","versions":["1.5.13"],"available":[{"date":"2024-12-21","kind":"first-observed","version":"1.5.13"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12801","cwe":"CWE-918","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12801","date":"2026-10-08","epss":0.00226,"percentile":0.12203}],"risk":0.06102,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-12801","https://logback.qos.ch/news.html#1.5.13","https://github.com/qos-ch/logback/commit/5f05041cba4c4ac0a62748c5c527a2da48999f2d","https://logback.qos.ch/news.html#1.3.15"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-6v67-2wr5-gvf4","description":"QOS.CH logback-core Server-Side Request Forgery vulnerability"},"relatedVulnerabilities":[{"id":"CVE-2024-12801","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:D/RE:X/U:Clear","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-12801","cwe":"CWE-918","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2024-12801","date":"2026-10-08","epss":0.00226,"percentile":0.12203}],"urls":["https://logback.qos.ch/news.html#1.3.15","https://logback.qos.ch/news.html#1.5.13"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-12801","description":"Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to \nforge requests by compromising logback configuration files in XML.\n\n\n\nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files."}]},{"artifact":{"id":"9f5c7138c38f1915","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.2.14-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-96674","versionConstraint":"<= 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-96674","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96674","cwe":"CWE-190","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96674","date":"2026-10-08","epss":0.00115,"percentile":0.01438}],"risk":0.0552,"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521","https://github.com/alsa-project/alsa-lib/pull/527","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96674","description":"alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application."},"relatedVulnerabilities":[]},{"artifact":{"id":"ef6ba7fd852d826b","cpes":["cpe:2.3:a:org.eclipse.jetty.http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty.http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse-jetty-project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse_jetty_project:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:org.eclipse.jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty-http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty_http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty-http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty_http:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:eclipse:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:jetty:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:jetty:http:11.0.15:*:*:*:*:*:*:*","cpe:2.3:a:http:http:11.0.15:*:*:*:*:*:*:*"],"name":"jetty-http","purl":"pkg:maven/org.eclipse.jetty/jetty-http@11.0.15","type":"java-archive","version":"11.0.15","language":"java","licenses":["https://www.eclipse.org/legal/epl-2.0, https://www.apache.org/licenses/LICENSE-2.0"],"metadata":{"pomGroupID":"org.eclipse.jetty","virtualPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","manifestName":"","pomArtifactID":"jetty-http","archiveDigests":[{"value":"06eb099ce51496de87ecfe9b8c62c2e8f3f5e848","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:jetty-http-11.0.15.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-wjpw-4j6x-6rwh","versionConstraint":">=11.0.0,<=11.0.26 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"org.eclipse.jetty:jetty-http","version":"11.0.15"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-wjpw-4j6x-6rwh","fix":{"state":"not-fixed","versions":[]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2025-11143","date":"2026-10-08","epss":0.00161,"percentile":0.04733}],"risk":0.053935,"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh","https://nvd.nist.gov/vuln/detail/CVE-2025-11143","https://github.com/user-attachments/files/22222625/Java.Eclipse.Jetty.Report_.Incorrect.Parsing.Priority.of.the.IPv6.Hostname.Delimeter.pdf","https://github.com/user-attachments/files/22222626/Java.Eclipse.Jetty.Report_.The.Parsing.Priority.of.the.Delimiter.pdf","https://github.com/user-attachments/files/22222627/Java.Eclipse.Jetty.Report_.Parsing.Difference.Due.to.Deformed.Scheme.pdf","https://github.com/user-attachments/files/22222630/Java.Eclipse.Jetty.Report_.Improper.IPv4-mapped.IPv6.Parsing.pdf"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-wjpw-4j6x-6rwh","description":"org.eclipse.jetty:jetty-http has different parsing of invalid URIs"},"relatedVulnerabilities":[{"id":"CVE-2025-11143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"emo@eclipse.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-11143","cwe":"CWE-20","type":"Secondary","source":"emo@eclipse.org"}],"epss":[{"cve":"CVE-2025-11143","date":"2026-10-08","epss":0.00161,"percentile":0.04733}],"urls":["https://github.com/jetty/jetty.project/security/advisories/GHSA-wjpw-4j6x-6rwh"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-11143","description":"The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from one that generates a response. At the very least, differential parsing may divulge implementation details."}]},{"artifact":{"id":"9f5c7138c38f1915","cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_project:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa-lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa_lib:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa-lib:1.2.14-r0:*:*:*:*:*:*:*","cpe:2.3:a:alsa:alsa_lib:1.2.14-r0:*:*:*:*:*:*:*"],"name":"alsa-lib","purl":"pkg:apk/alpine/alsa-lib@1.2.14-r0?arch=x86_64&distro=alpine-3.22.6","type":"apk","version":"1.2.14-r0","language":"","licenses":["LGPL-2.1-or-later"],"metadata":{"Arch":"x86_64","files":[{"path":"/etc"},{"path":"/etc/alsa"},{"path":"/etc/alsa/conf.d"},{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/aserver"},{"path":"/usr/lib"},{"path":"/usr/lib/libasound.so.2"},{"path":"/usr/lib/libasound.so.2.0.0"},{"path":"/usr/lib/libatopology.so.2"},{"path":"/usr/lib/libatopology.so.2.0.0"},{"path":"/usr/share"},{"path":"/usr/share/alsa"},{"path":"/usr/share/alsa/alsa.conf"},{"path":"/usr/share/alsa/cards"},{"path":"/usr/share/alsa/cards/AACI.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-MODEM.conf"},{"path":"/usr/share/alsa/cards/ATIIXP-SPDMA.conf"},{"path":"/usr/share/alsa/cards/ATIIXP.conf"},{"path":"/usr/share/alsa/cards/AU8810.conf"},{"path":"/usr/share/alsa/cards/AU8820.conf"},{"path":"/usr/share/alsa/cards/AU8830.conf"},{"path":"/usr/share/alsa/cards/Audigy.conf"},{"path":"/usr/share/alsa/cards/Audigy2.conf"},{"path":"/usr/share/alsa/cards/Aureon51.conf"},{"path":"/usr/share/alsa/cards/Aureon71.conf"},{"path":"/usr/share/alsa/cards/CA0106.conf"},{"path":"/usr/share/alsa/cards/CMI8338-SWIEC.conf"},{"path":"/usr/share/alsa/cards/CMI8338.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC6.conf"},{"path":"/usr/share/alsa/cards/CMI8738-MC8.conf"},{"path":"/usr/share/alsa/cards/CMI8788.conf"},{"path":"/usr/share/alsa/cards/CS46xx.conf"},{"path":"/usr/share/alsa/cards/EMU10K1.conf"},{"path":"/usr/share/alsa/cards/EMU10K1X.conf"},{"path":"/usr/share/alsa/cards/ENS1370.conf"},{"path":"/usr/share/alsa/cards/ENS1371.conf"},{"path":"/usr/share/alsa/cards/ES1968.conf"},{"path":"/usr/share/alsa/cards/Echo_Echo3G.conf"},{"path":"/usr/share/alsa/cards/FM801.conf"},{"path":"/usr/share/alsa/cards/FWSpeakers.conf"},{"path":"/usr/share/alsa/cards/FireWave.conf"},{"path":"/usr/share/alsa/cards/GUS.conf"},{"path":"/usr/share/alsa/cards/HDA-Intel.conf"},{"path":"/usr/share/alsa/cards/HdmiLpeAudio.conf"},{"path":"/usr/share/alsa/cards/ICE1712.conf"},{"path":"/usr/share/alsa/cards/ICE1724.conf"},{"path":"/usr/share/alsa/cards/ICH-MODEM.conf"},{"path":"/usr/share/alsa/cards/ICH.conf"},{"path":"/usr/share/alsa/cards/ICH4.conf"},{"path":"/usr/share/alsa/cards/Loopback.conf"},{"path":"/usr/share/alsa/cards/Maestro3.conf"},{"path":"/usr/share/alsa/cards/NFORCE.conf"},{"path":"/usr/share/alsa/cards/PC-Speaker.conf"},{"path":"/usr/share/alsa/cards/PMac.conf"},{"path":"/usr/share/alsa/cards/PMacToonie.conf"},{"path":"/usr/share/alsa/cards/PS3.conf"},{"path":"/usr/share/alsa/cards/RME9636.conf"},{"path":"/usr/share/alsa/cards/RME9652.conf"},{"path":"/usr/share/alsa/cards/SB-XFi.conf"},{"path":"/usr/share/alsa/cards/SI7018.conf"},{"path":"/usr/share/alsa/cards/TRID4DWAVENX.conf"},{"path":"/usr/share/alsa/cards/USB-Audio.conf"},{"path":"/usr/share/alsa/cards/VIA686A.conf"},{"path":"/usr/share/alsa/cards/VIA8233.conf"},{"path":"/usr/share/alsa/cards/VIA8233A.conf"},{"path":"/usr/share/alsa/cards/VIA8237.conf"},{"path":"/usr/share/alsa/cards/VX222.conf"},{"path":"/usr/share/alsa/cards/VXPocket.conf"},{"path":"/usr/share/alsa/cards/VXPocket440.conf"},{"path":"/usr/share/alsa/cards/YMF744.conf"},{"path":"/usr/share/alsa/cards/aliases.conf"},{"path":"/usr/share/alsa/cards/pistachio-card.conf"},{"path":"/usr/share/alsa/cards/vc4-hdmi.conf"},{"path":"/usr/share/alsa/ctl"},{"path":"/usr/share/alsa/ctl/default.conf"},{"path":"/usr/share/alsa/pcm"},{"path":"/usr/share/alsa/pcm/center_lfe.conf"},{"path":"/usr/share/alsa/pcm/default.conf"},{"path":"/usr/share/alsa/pcm/dmix.conf"},{"path":"/usr/share/alsa/pcm/dpl.conf"},{"path":"/usr/share/alsa/pcm/dsnoop.conf"},{"path":"/usr/share/alsa/pcm/front.conf"},{"path":"/usr/share/alsa/pcm/hdmi.conf"},{"path":"/usr/share/alsa/pcm/iec958.conf"},{"path":"/usr/share/alsa/pcm/modem.conf"},{"path":"/usr/share/alsa/pcm/rear.conf"},{"path":"/usr/share/alsa/pcm/side.conf"},{"path":"/usr/share/alsa/pcm/surround21.conf"},{"path":"/usr/share/alsa/pcm/surround40.conf"},{"path":"/usr/share/alsa/pcm/surround41.conf"},{"path":"/usr/share/alsa/pcm/surround50.conf"},{"path":"/usr/share/alsa/pcm/surround51.conf"},{"path":"/usr/share/alsa/pcm/surround71.conf"}]},"locations":[{"path":"/lib/apk/db/installed","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"alsa-lib"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-96675","versionConstraint":"<= 1.2.16.1 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:alsa-project:alsa-lib:1.2.14:*:*:*:*:*:*:*"],"package":{"name":"alsa-lib","version":"1.2.14-r0"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-96675","fix":{"state":"","versions":[]},"cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.8},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-96675","cwe":"CWE-129","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-96675","date":"2026-10-08","epss":0.00111,"percentile":0.01223}],"risk":0.05022750000000001,"urls":["https://github.com/alsa-project/alsa-lib","https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131","https://github.com/alsa-project/alsa-lib/pull/527","https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-96675","description":"alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort."},"relatedVulnerabilities":[]},{"artifact":{"id":"c0144d0bb00d6450","cpes":["cpe:2.3:a:logback-core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback-core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback_core:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:logback:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos-ch:logback_core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback-core:1.5.6:*:*:*:*:*:*:*","cpe:2.3:a:qos_ch:logback_core:1.5.6:*:*:*:*:*:*:*"],"name":"logback-core","purl":"pkg:maven/ch.qos.logback/logback-core@1.5.6","type":"java-archive","version":"1.5.6","language":"java","licenses":["http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html"],"metadata":{"pomGroupID":"ch.qos.logback","virtualPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","manifestName":"","pomArtifactID":"logback-core","archiveDigests":[{"value":"41cbe874701200c5624c19e0ab50d1b88dfcc77d","algorithm":"sha1"}]},"locations":[{"path":"/app/ubooquity/Ubooquity.jar","layerID":"sha256:dca8a342f76c0fd65fe7b934ff7b48d78048e62dea1ea36951aae1cb7b7aee03","accessPath":"/app/ubooquity/Ubooquity.jar:logback-core-1.5.6.jar","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"JavaMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.5.25"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qqpg-mvqg-649v","versionConstraint":"<1.5.25 (unknown)"},"matcher":"java-matcher","searchedBy":{"package":{"name":"ch.qos.logback:logback-core","version":"1.5.6"},"language":"java","namespace":"github:language:java"}}],"vulnerability":{"id":"GHSA-qqpg-mvqg-649v","fix":{"state":"fixed","versions":["1.5.25"],"available":[{"date":"2026-01-23","kind":"first-observed","version":"1.5.25"}]},"cvss":[{"type":"Secondary","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1225","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-1225","date":"2026-10-08","epss":0.00165,"percentile":0.0518}],"risk":0.039599999999999996,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-1225","https://logback.qos.ch/news.html#1.5.25","https://github.com/qos-ch/logback/issues/997","https://github.com/qos-ch/logback/commit/1f97ae1844b1be8486e4e9cade98d7123d3eded5"],"severity":"Low","namespace":"github:language:java","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qqpg-mvqg-649v","description":"Logback allows an attacker to instantiate classes already present on the class path"},"relatedVulnerabilities":[{"id":"CVE-2026-1225","cvss":[{"type":"Secondary","source":"vulnerability@ncsc.ch","vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:M/U:Green","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-1225","cwe":"CWE-20","type":"Secondary","source":"vulnerability@ncsc.ch"}],"epss":[{"cve":"CVE-2026-1225","date":"2026-10-08","epss":0.00165,"percentile":0.0518}],"urls":["https://logback.qos.ch/news.html#1.5.25"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-1225","description":"ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.\n\n\n\n\nThe instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must  have write access to a \nconfiguration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado."}]}],"grade":"F","score":"0.00","as_of":"2026-10-09T22:29:10.398Z","grype_db_version":"2026-10-09T06:32:32.000Z"}