{"grype_matches":[{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.31.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-v778-237x-gjrc","versionConstraint":"<0.31.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-v778-237x-gjrc","fix":{"state":"fixed","versions":["0.31.0"],"available":[{"date":"2024-12-12","kind":"first-observed","version":"0.31.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45337","date":"2026-10-08","epss":0.03181,"percentile":0.87682}],"risk":2.878805,"urls":["https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909","https://go.dev/cl/635315","https://go.dev/issue/70779","https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ","https://pkg.go.dev/vuln/GO-2024-3321","https://nvd.nist.gov/vuln/detail/CVE-2024-45337","http://www.openwall.com/lists/oss-security/2024/12/11/2","https://security.netapp.com/advisory/ntap-20250131-0007"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-v778-237x-gjrc","description":"Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto"},"relatedVulnerabilities":[{"id":"CVE-2024-45337","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2024-45337","date":"2026-10-08","epss":0.03181,"percentile":0.87682}],"urls":["https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909","https://go.dev/cl/635315","https://go.dev/issue/70779","https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ","https://pkg.go.dev/vuln/GO-2024-3321","http://www.openwall.com/lists/oss-security/2024/12/11/2","https://security.netapp.com/advisory/ntap-20250131-0007/"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-45337","description":"Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that \"A call to this function does not guarantee that the key offered is in fact used to authenticate.\" Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B for which the attacker does not actually control the private key. Since this API is widely misused, as a partial mitigation golang.org/x/cry...@v0.31.0 enforces the property that, when successfully authenticating via public key, the last key passed to ServerConfig.PublicKeyCallback will be the key used to authenticate the connection. PublicKeyCallback will now be called multiple times with the same key, if necessary. Note that the client may still not control the last key passed to PublicKeyCallback if the connection is then authenticated with a different method, such as PasswordCallback, KeyboardInteractiveCallback, or NoClientAuth. Users should be using the Extensions field of the Permissions return value from the various authentication callbacks to record data associated with the authentication attempt instead of referencing external state. Once the connection is established the state corresponding to the successful authentication attempt can be retrieved via the ServerConn.Permissions field. Note that some third-party libraries misuse the Permissions type by sharing it across authentication attempts; users of third-party libraries should refer to the relevant projects for guidance."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4341","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4341","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"risk":1.7445,"urls":["https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736712","description":"The net/url package does not set a limit on the number of query parameters in a query.\n\nWhile the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61726","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2025-61726","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2025-61726","date":"2026-10-08","epss":0.02326,"percentile":0.82985}],"urls":["https://go.dev/cl/736712","https://go.dev/issue/77101","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4341","https://access.redhat.com/errata/RHSA-2026:10096","https://access.redhat.com/errata/RHSA-2026:10104","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:11408","https://access.redhat.com/errata/RHSA-2026:11414","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12279","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13542","https://access.redhat.com/errata/RHSA-2026:13548","https://access.redhat.com/errata/RHSA-2026:13571","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:15984","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17446","https://access.redhat.com/errata/RHSA-2026:17460","https://access.redhat.com/errata/RHSA-2026:17463","https://access.redhat.com/errata/RHSA-2026:17468","https://access.redhat.com/errata/RHSA-2026:17595","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:18913","https://access.redhat.com/errata/RHSA-2026:19013","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19712","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26420","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:2681","https://access.redhat.com/errata/RHSA-2026:2706","https://access.redhat.com/errata/RHSA-2026:2708","https://access.redhat.com/errata/RHSA-2026:2709","https://access.redhat.com/errata/RHSA-2026:2754","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:2844","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:2914","https://access.redhat.com/errata/RHSA-2026:2920","https://access.redhat.com/errata/RHSA-2026:3035","https://access.redhat.com/errata/RHSA-2026:3040","https://access.redhat.com/errata/RHSA-2026:3089","https://access.redhat.com/errata/RHSA-2026:3092","https://access.redhat.com/errata/RHSA-2026:3184","https://access.redhat.com/errata/RHSA-2026:3186","https://access.redhat.com/errata/RHSA-2026:3187","https://access.redhat.com/errata/RHSA-2026:3188","https://access.redhat.com/errata/RHSA-2026:3192","https://access.redhat.com/errata/RHSA-2026:3193","https://access.redhat.com/errata/RHSA-2026:3291","https://access.redhat.com/errata/RHSA-2026:3296","https://access.redhat.com/errata/RHSA-2026:3297","https://access.redhat.com/errata/RHSA-2026:3298","https://access.redhat.com/errata/RHSA-2026:3336","https://access.redhat.com/errata/RHSA-2026:3337","https://access.redhat.com/errata/RHSA-2026:3340","https://access.redhat.com/errata/RHSA-2026:3341","https://access.redhat.com/errata/RHSA-2026:3343","https://access.redhat.com/errata/RHSA-2026:3391","https://access.redhat.com/errata/RHSA-2026:3416","https://access.redhat.com/errata/RHSA-2026:3427","https://access.redhat.com/errata/RHSA-2026:3459","https://access.redhat.com/errata/RHSA-2026:3468","https://access.redhat.com/errata/RHSA-2026:3469","https://access.redhat.com/errata/RHSA-2026:3470","https://access.redhat.com/errata/RHSA-2026:3471","https://access.redhat.com/errata/RHSA-2026:3472","https://access.redhat.com/errata/RHSA-2026:3473","https://access.redhat.com/errata/RHSA-2026:3489","https://access.redhat.com/errata/RHSA-2026:3506","https://access.redhat.com/errata/RHSA-2026:3556","https://access.redhat.com/errata/RHSA-2026:3559","https://access.redhat.com/errata/RHSA-2026:3668","https://access.redhat.com/errata/RHSA-2026:3669","https://access.redhat.com/errata/RHSA-2026:36873","https://access.redhat.com/errata/RHSA-2026:36882","https://access.redhat.com/errata/RHSA-2026:3699","https://access.redhat.com/errata/RHSA-2026:3713","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:3752","https://access.redhat.com/errata/RHSA-2026:3753","https://access.redhat.com/errata/RHSA-2026:3782","https://access.redhat.com/errata/RHSA-2026:3812","https://access.redhat.com/errata/RHSA-2026:3813","https://access.redhat.com/errata/RHSA-2026:3814","https://access.redhat.com/errata/RHSA-2026:3815","https://access.redhat.com/errata/RHSA-2026:3816","https://access.redhat.com/errata/RHSA-2026:3817","https://access.redhat.com/errata/RHSA-2026:3818","https://access.redhat.com/errata/RHSA-2026:3820","https://access.redhat.com/errata/RHSA-2026:3821","https://access.redhat.com/errata/RHSA-2026:3822","https://access.redhat.com/errata/RHSA-2026:3831","https://access.redhat.com/errata/RHSA-2026:3833","https://access.redhat.com/errata/RHSA-2026:3835","https://access.redhat.com/errata/RHSA-2026:3836","https://access.redhat.com/errata/RHSA-2026:3838","https://access.redhat.com/errata/RHSA-2026:3839","https://access.redhat.com/errata/RHSA-2026:3840","https://access.redhat.com/errata/RHSA-2026:3841","https://access.redhat.com/errata/RHSA-2026:3843","https://access.redhat.com/errata/RHSA-2026:3854","https://access.redhat.com/errata/RHSA-2026:3855","https://access.redhat.com/errata/RHSA-2026:3856","https://access.redhat.com/errata/RHSA-2026:3864","https://access.redhat.com/errata/RHSA-2026:3869","https://access.redhat.com/errata/RHSA-2026:3874","https://access.redhat.com/errata/RHSA-2026:3875","https://access.redhat.com/errata/RHSA-2026:3879","https://access.redhat.com/errata/RHSA-2026:3880","https://access.redhat.com/errata/RHSA-2026:3884","https://access.redhat.com/errata/RHSA-2026:3898","https://access.redhat.com/errata/RHSA-2026:3905","https://access.redhat.com/errata/RHSA-2026:3906","https://access.redhat.com/errata/RHSA-2026:3928","https://access.redhat.com/errata/RHSA-2026:3929","https://access.redhat.com/errata/RHSA-2026:3930","https://access.redhat.com/errata/RHSA-2026:3931","https://access.redhat.com/errata/RHSA-2026:3932","https://access.redhat.com/errata/RHSA-2026:3958","https://access.redhat.com/errata/RHSA-2026:3959","https://access.redhat.com/errata/RHSA-2026:3960","https://access.redhat.com/errata/RHSA-2026:3970","https://access.redhat.com/errata/RHSA-2026:3971","https://access.redhat.com/errata/RHSA-2026:3972","https://access.redhat.com/errata/RHSA-2026:3973","https://access.redhat.com/errata/RHSA-2026:3974","https://access.redhat.com/errata/RHSA-2026:3977","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:3985","https://access.redhat.com/errata/RHSA-2026:40924","https://access.redhat.com/errata/RHSA-2026:4164","https://access.redhat.com/errata/RHSA-2026:4166","https://access.redhat.com/errata/RHSA-2026:4170","https://access.redhat.com/errata/RHSA-2026:4174","https://access.redhat.com/errata/RHSA-2026:4177","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41941","https://access.redhat.com/errata/RHSA-2026:4211","https://access.redhat.com/errata/RHSA-2026:4220","https://access.redhat.com/errata/RHSA-2026:4256","https://access.redhat.com/errata/RHSA-2026:4264","https://access.redhat.com/errata/RHSA-2026:4267","https://access.redhat.com/errata/RHSA-2026:4270","https://access.redhat.com/errata/RHSA-2026:4276","https://access.redhat.com/errata/RHSA-2026:4434","https://access.redhat.com/errata/RHSA-2026:4435","https://access.redhat.com/errata/RHSA-2026:4460","https://access.redhat.com/errata/RHSA-2026:4466","https://access.redhat.com/errata/RHSA-2026:4467","https://access.redhat.com/errata/RHSA-2026:4498","https://access.redhat.com/errata/RHSA-2026:4500","https://access.redhat.com/errata/RHSA-2026:4510","https://access.redhat.com/errata/RHSA-2026:4511","https://access.redhat.com/errata/RHSA-2026:4672","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:4753","https://access.redhat.com/errata/RHSA-2026:4892","https://access.redhat.com/errata/RHSA-2026:4901","https://access.redhat.com/errata/RHSA-2026:4907","https://access.redhat.com/errata/RHSA-2026:4939","https://access.redhat.com/errata/RHSA-2026:4942","https://access.redhat.com/errata/RHSA-2026:4943","https://access.redhat.com/errata/RHSA-2026:4952","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5022","https://access.redhat.com/errata/RHSA-2026:5030","https://access.redhat.com/errata/RHSA-2026:5031","https://access.redhat.com/errata/RHSA-2026:5076","https://access.redhat.com/errata/RHSA-2026:5077","https://access.redhat.com/errata/RHSA-2026:5078","https://access.redhat.com/errata/RHSA-2026:5079","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:5129","https://access.redhat.com/errata/RHSA-2026:5130","https://access.redhat.com/errata/RHSA-2026:5131","https://access.redhat.com/errata/RHSA-2026:5132","https://access.redhat.com/errata/RHSA-2026:5145","https://access.redhat.com/errata/RHSA-2026:5146","https://access.redhat.com/errata/RHSA-2026:5168","https://access.redhat.com/errata/RHSA-2026:5327","https://access.redhat.com/errata/RHSA-2026:5394","https://access.redhat.com/errata/RHSA-2026:5439","https://access.redhat.com/errata/RHSA-2026:5444","https://access.redhat.com/errata/RHSA-2026:5447","https://access.redhat.com/errata/RHSA-2026:5452","https://access.redhat.com/errata/RHSA-2026:5461","https://access.redhat.com/errata/RHSA-2026:5463","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5533","https://access.redhat.com/errata/RHSA-2026:5544","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:5636","https://access.redhat.com/errata/RHSA-2026:56366","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:5645","https://access.redhat.com/errata/RHSA-2026:5649","https://access.redhat.com/errata/RHSA-2026:5665","https://access.redhat.com/errata/RHSA-2026:57013","https://access.redhat.com/errata/RHSA-2026:5807","https://access.redhat.com/errata/RHSA-2026:5851","https://access.redhat.com/errata/RHSA-2026:5852","https://access.redhat.com/errata/RHSA-2026:5853","https://access.redhat.com/errata/RHSA-2026:5948","https://access.redhat.com/errata/RHSA-2026:5950","https://access.redhat.com/errata/RHSA-2026:5952","https://access.redhat.com/errata/RHSA-2026:5968","https://access.redhat.com/errata/RHSA-2026:6184","https://access.redhat.com/errata/RHSA-2026:6192","https://access.redhat.com/errata/RHSA-2026:6226","https://access.redhat.com/errata/RHSA-2026:6251","https://access.redhat.com/errata/RHSA-2026:6277","https://access.redhat.com/errata/RHSA-2026:6278","https://access.redhat.com/errata/RHSA-2026:6428","https://access.redhat.com/errata/RHSA-2026:6429","https://access.redhat.com/errata/RHSA-2026:6497","https://access.redhat.com/errata/RHSA-2026:6554","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:6567","https://access.redhat.com/errata/RHSA-2026:6568","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:7052","https://access.redhat.com/errata/RHSA-2026:7249","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7676","https://access.redhat.com/errata/RHSA-2026:7854","https://access.redhat.com/errata/RHSA-2026:7942","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8218","https://access.redhat.com/errata/RHSA-2026:8229","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8431","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9848","https://access.redhat.com/security/cve/CVE-2025-61726","https://bugzilla.redhat.com/show_bug.cgi?id=2434432","https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726","description":"The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4337","versionConstraint":"<1.24.13||>=1.25.0-0,<1.25.7||>=1.26.0-rc.1,<1.26.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4337","fix":{"state":"fixed","versions":["1.24.13","1.25.7","1.26.0-rc.3"],"available":[{"date":"2026-02-04","kind":"release","version":"1.24.13"},{"date":"2026-02-04","kind":"release","version":"1.25.7"},{"date":"2026-02-04","kind":"release","version":"1.26.0-rc.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"risk":0.8692500000000001,"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217"],"severity":"Critical","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-68121","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","metrics":{"baseScore":10,"impactScore":6.1,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-68121","cwe":"CWE-295","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-68121","date":"2026-10-08","epss":0.00915,"percentile":0.58934}],"urls":["https://go.dev/cl/737700","https://go.dev/issue/77217","https://groups.google.com/g/golang-announce/c/K09ubi9FQFk","https://pkg.go.dev/vuln/GO-2026-4337"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-68121","description":"During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and mutates the returned Config, or uses Config.GetConfigForClient. This can cause a client to resume a session with a server that it would not have resumed with during the initial handshake, or cause a server to resume a session with a client that it would not have resumed with during the initial handshake."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.35.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-hcg3-q754-cr77","versionConstraint":"<0.35.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-hcg3-q754-cr77","fix":{"state":"fixed","versions":["0.35.0"],"available":[{"date":"2025-04-15","kind":"first-observed","version":"0.35.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22869","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22869","date":"2026-10-08","epss":0.00939,"percentile":0.59727}],"risk":0.70425,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-22869","https://go.dev/cl/652135","https://go.dev/issue/71931","https://pkg.go.dev/vuln/GO-2025-3487","https://security.netapp.com/advisory/ntap-20250411-0010","https://github.com/golang/crypto/commit/7292932d45d55c7199324ab0027cc86e8198aa22","https://go-review.googlesource.com/c/crypto/+/652135"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-hcg3-q754-cr77","description":"golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange"},"relatedVulnerabilities":[{"id":"CVE-2025-22869","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-22869","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-22869","date":"2026-10-08","epss":0.00939,"percentile":0.59727}],"urls":["https://go.dev/cl/652135","https://go.dev/issue/71931","https://pkg.go.dev/vuln/GO-2025-3487","https://security.netapp.com/advisory/ntap-20250411-0010/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-22869","description":"SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-7210","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-7210","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"risk":0.6755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-7210"},"relatedVulnerabilities":[{"id":"CVE-2026-7210","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-7210","cwe":"CWE-331","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-7210","date":"2026-10-08","epss":0.01351,"percentile":0.70668}],"urls":["https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4","https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b2566","https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc56","https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640b","https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc0286","https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27a","https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f","https://github.com/python/cpython/issues/149018","https://github.com/python/cpython/pull/149023","https://mail.python.org/archives/list/security-announce@python.org/thread/PNY5OMBDPM2FRUZTWFFPJ6LISWKV627K/","http://www.openwall.com/lists/oss-security/2026/05/11/13","http://www.openwall.com/lists/oss-security/2026/05/11/8"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-7210","description":"`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\\r\\n\\r\\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f5wc-c3c7-36mc","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-f5wc-c3c7-36mc","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39832","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39832","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39832","date":"2026-10-08","epss":0.00716,"percentile":0.52306}],"risk":0.64798,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39832","https://go.dev/cl/778642","https://go.dev/issue/79435","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://access.redhat.com/security/cve/CVE-2026-39832","https://bugzilla.redhat.com/show_bug.cgi?id=2480685","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f5wc-c3c7-36mc","description":"golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys"},"relatedVulnerabilities":[{"id":"CVE-2026-39832","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.7,"impactScore":5.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39832","cwe":"CWE-502","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39832","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39832","date":"2026-10-08","epss":0.00716,"percentile":0.52306}],"urls":["https://go.dev/cl/778640","https://go.dev/cl/778641","https://go.dev/issue/79435","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39832","https://bugzilla.redhat.com/show_bug.cgi?id=2480685","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39832","description":"When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4601","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4601","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"risk":0.6255000000000001,"urls":["https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/752180","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."},"relatedVulnerabilities":[{"id":"CVE-2026-25679","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-25679","cwe":"CWE-425","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-25679","cwe":"CWE-1286","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-25679","date":"2026-10-08","epss":0.00834,"percentile":0.56374}],"urls":["https://go.dev/cl/752180","https://go.dev/issue/77578","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4601","https://access.redhat.com/errata/RHSA-2026:10065","https://access.redhat.com/errata/RHSA-2026:10125","https://access.redhat.com/errata/RHSA-2026:10133","https://access.redhat.com/errata/RHSA-2026:10140","https://access.redhat.com/errata/RHSA-2026:10141","https://access.redhat.com/errata/RHSA-2026:10158","https://access.redhat.com/errata/RHSA-2026:10169","https://access.redhat.com/errata/RHSA-2026:10175","https://access.redhat.com/errata/RHSA-2026:10184","https://access.redhat.com/errata/RHSA-2026:10225","https://access.redhat.com/errata/RHSA-2026:10250","https://access.redhat.com/errata/RHSA-2026:10701","https://access.redhat.com/errata/RHSA-2026:10712","https://access.redhat.com/errata/RHSA-2026:10929","https://access.redhat.com/errata/RHSA-2026:11217","https://access.redhat.com/errata/RHSA-2026:11375","https://access.redhat.com/errata/RHSA-2026:11412","https://access.redhat.com/errata/RHSA-2026:11413","https://access.redhat.com/errata/RHSA-2026:11686","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:11747","https://access.redhat.com/errata/RHSA-2026:11749","https://access.redhat.com/errata/RHSA-2026:11768","https://access.redhat.com/errata/RHSA-2026:11800","https://access.redhat.com/errata/RHSA-2026:11856","https://access.redhat.com/errata/RHSA-2026:11916","https://access.redhat.com/errata/RHSA-2026:11996","https://access.redhat.com/errata/RHSA-2026:12028","https://access.redhat.com/errata/RHSA-2026:12029","https://access.redhat.com/errata/RHSA-2026:12030","https://access.redhat.com/errata/RHSA-2026:12031","https://access.redhat.com/errata/RHSA-2026:12032","https://access.redhat.com/errata/RHSA-2026:12033","https://access.redhat.com/errata/RHSA-2026:12282","https://access.redhat.com/errata/RHSA-2026:13508","https://access.redhat.com/errata/RHSA-2026:13512","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13642","https://access.redhat.com/errata/RHSA-2026:13643","https://access.redhat.com/errata/RHSA-2026:13671","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14100","https://access.redhat.com/errata/RHSA-2026:14774","https://access.redhat.com/errata/RHSA-2026:14868","https://access.redhat.com/errata/RHSA-2026:14879","https://access.redhat.com/errata/RHSA-2026:15091","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16696","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17040","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:17598","https://access.redhat.com/errata/RHSA-2026:19017","https://access.redhat.com/errata/RHSA-2026:19022","https://access.redhat.com/errata/RHSA-2026:19026","https://access.redhat.com/errata/RHSA-2026:19027","https://access.redhat.com/errata/RHSA-2026:19031","https://access.redhat.com/errata/RHSA-2026:19032","https://access.redhat.com/errata/RHSA-2026:19049","https://access.redhat.com/errata/RHSA-2026:19055","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19128","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19181","https://access.redhat.com/errata/RHSA-2026:19184","https://access.redhat.com/errata/RHSA-2026:19185","https://access.redhat.com/errata/RHSA-2026:19207","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19475","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:20041","https://access.redhat.com/errata/RHSA-2026:20088","https://access.redhat.com/errata/RHSA-2026:20581","https://access.redhat.com/errata/RHSA-2026:20582","https://access.redhat.com/errata/RHSA-2026:20584","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21657","https://access.redhat.com/errata/RHSA-2026:21691","https://access.redhat.com/errata/RHSA-2026:21696","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22627","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22733","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24386","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:25043","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26445","https://access.redhat.com/errata/RHSA-2026:26527","https://access.redhat.com/errata/RHSA-2026:26541","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28893","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:5110","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52389","https://access.redhat.com/errata/RHSA-2026:52390","https://access.redhat.com/errata/RHSA-2026:52391","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:5549","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:5941","https://access.redhat.com/errata/RHSA-2026:5942","https://access.redhat.com/errata/RHSA-2026:5943","https://access.redhat.com/errata/RHSA-2026:5944","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:6341","https://access.redhat.com/errata/RHSA-2026:6344","https://access.redhat.com/errata/RHSA-2026:6382","https://access.redhat.com/errata/RHSA-2026:6383","https://access.redhat.com/errata/RHSA-2026:6388","https://access.redhat.com/errata/RHSA-2026:6564","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:6720","https://access.redhat.com/errata/RHSA-2026:6802","https://access.redhat.com/errata/RHSA-2026:6949","https://access.redhat.com/errata/RHSA-2026:7005","https://access.redhat.com/errata/RHSA-2026:7009","https://access.redhat.com/errata/RHSA-2026:7011","https://access.redhat.com/errata/RHSA-2026:7259","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7315","https://access.redhat.com/errata/RHSA-2026:7328","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/errata/RHSA-2026:7665","https://access.redhat.com/errata/RHSA-2026:7669","https://access.redhat.com/errata/RHSA-2026:7674","https://access.redhat.com/errata/RHSA-2026:7833","https://access.redhat.com/errata/RHSA-2026:7834","https://access.redhat.com/errata/RHSA-2026:7876","https://access.redhat.com/errata/RHSA-2026:7877","https://access.redhat.com/errata/RHSA-2026:7878","https://access.redhat.com/errata/RHSA-2026:7879","https://access.redhat.com/errata/RHSA-2026:7883","https://access.redhat.com/errata/RHSA-2026:7992","https://access.redhat.com/errata/RHSA-2026:8151","https://access.redhat.com/errata/RHSA-2026:8167","https://access.redhat.com/errata/RHSA-2026:8314","https://access.redhat.com/errata/RHSA-2026:8322","https://access.redhat.com/errata/RHSA-2026:8324","https://access.redhat.com/errata/RHSA-2026:8337","https://access.redhat.com/errata/RHSA-2026:8338","https://access.redhat.com/errata/RHSA-2026:8433","https://access.redhat.com/errata/RHSA-2026:8434","https://access.redhat.com/errata/RHSA-2026:8456","https://access.redhat.com/errata/RHSA-2026:8483","https://access.redhat.com/errata/RHSA-2026:8484","https://access.redhat.com/errata/RHSA-2026:8490","https://access.redhat.com/errata/RHSA-2026:8491","https://access.redhat.com/errata/RHSA-2026:8493","https://access.redhat.com/errata/RHSA-2026:8840","https://access.redhat.com/errata/RHSA-2026:8841","https://access.redhat.com/errata/RHSA-2026:8842","https://access.redhat.com/errata/RHSA-2026:8845","https://access.redhat.com/errata/RHSA-2026:8847","https://access.redhat.com/errata/RHSA-2026:8848","https://access.redhat.com/errata/RHSA-2026:8849","https://access.redhat.com/errata/RHSA-2026:8851","https://access.redhat.com/errata/RHSA-2026:8852","https://access.redhat.com/errata/RHSA-2026:8853","https://access.redhat.com/errata/RHSA-2026:8855","https://access.redhat.com/errata/RHSA-2026:8856","https://access.redhat.com/errata/RHSA-2026:8860","https://access.redhat.com/errata/RHSA-2026:8877","https://access.redhat.com/errata/RHSA-2026:8878","https://access.redhat.com/errata/RHSA-2026:8879","https://access.redhat.com/errata/RHSA-2026:8881","https://access.redhat.com/errata/RHSA-2026:8882","https://access.redhat.com/errata/RHSA-2026:8930","https://access.redhat.com/errata/RHSA-2026:8931","https://access.redhat.com/errata/RHSA-2026:8949","https://access.redhat.com/errata/RHSA-2026:9043","https://access.redhat.com/errata/RHSA-2026:9044","https://access.redhat.com/errata/RHSA-2026:9052","https://access.redhat.com/errata/RHSA-2026:9090","https://access.redhat.com/errata/RHSA-2026:9093","https://access.redhat.com/errata/RHSA-2026:9094","https://access.redhat.com/errata/RHSA-2026:9097","https://access.redhat.com/errata/RHSA-2026:9098","https://access.redhat.com/errata/RHSA-2026:9108","https://access.redhat.com/errata/RHSA-2026:9109","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/errata/RHSA-2026:9434","https://access.redhat.com/errata/RHSA-2026:9435","https://access.redhat.com/errata/RHSA-2026:9436","https://access.redhat.com/errata/RHSA-2026:9439","https://access.redhat.com/errata/RHSA-2026:9440","https://access.redhat.com/errata/RHSA-2026:9448","https://access.redhat.com/errata/RHSA-2026:9453","https://access.redhat.com/errata/RHSA-2026:9461","https://access.redhat.com/errata/RHSA-2026:9695","https://access.redhat.com/errata/RHSA-2026:9742","https://access.redhat.com/errata/RHSA-2026:9872","https://access.redhat.com/security/cve/CVE-2026-25679","https://bugzilla.redhat.com/show_bug.cgi?id=2445356","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-25679","description":"url.Parse insufficiently validated the host/authority component and accepted some invalid URLs."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4981","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4981","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"risk":0.60975,"urls":["https://go.dev/cl/767860","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78803","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."},"relatedVulnerabilities":[{"id":"CVE-2026-33811","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33811","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33811","cwe":"CWE-1341","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33811","date":"2026-10-08","epss":0.00813,"percentile":0.55713}],"urls":["https://go.dev/cl/767860","https://go.dev/issue/78803","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4981","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:35995","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36617","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36776","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:39266","https://access.redhat.com/errata/RHSA-2026:39272","https://access.redhat.com/errata/RHSA-2026:39319","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54556","https://access.redhat.com/errata/RHSA-2026:54584","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56790","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60302","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61313","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/security/cve/CVE-2026-33811","https://bugzilla.redhat.com/show_bug.cgi?id=2467822","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33811","description":"When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4977","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4977","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"risk":0.5984999999999999,"urls":["https://go.dev/cl/771520","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78987","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."},"relatedVulnerabilities":[{"id":"CVE-2026-42499","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42499","cwe":"CWE-1046","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42499","date":"2026-10-08","epss":0.00798,"percentile":0.5517}],"urls":["https://go.dev/cl/771520","https://go.dev/issue/78987","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4977","https://access.redhat.com/errata/RHSA-2026:17713","https://access.redhat.com/errata/RHSA-2026:17714","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:63163","https://access.redhat.com/errata/RHSA-2026:63332","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:64818","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67148","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-42499","https://bugzilla.redhat.com/show_bug.cgi?id=2467809","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42499","description":"Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-5cgq-3rg8-m6cv","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-5cgq-3rg8-m6cv","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42508","date":"2026-10-08","epss":0.00654,"percentile":0.49763}],"risk":0.59187,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-42508","https://go.dev/cl/781220","https://go.dev/issue/79568","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/security/cve/CVE-2026-42508","https://bugzilla.redhat.com/show_bug.cgi?id=2480688","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40138","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41064","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40945"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-5cgq-3rg8-m6cv","description":"golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status"},"relatedVulnerabilities":[{"id":"CVE-2026-42508","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-42508","cwe":"CWE-295","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-42508","date":"2026-10-08","epss":0.00654,"percentile":0.49763}],"urls":["https://go.dev/cl/781220","https://go.dev/issue/79568","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41064","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-42508","https://bugzilla.redhat.com/show_bug.cgi?id=2480688","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42508","description":"Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4986","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4986","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"risk":0.588,"urls":["https://go.dev/cl/759940","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78566","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-39820","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39820","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39820","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39820","date":"2026-10-08","epss":0.00784,"percentile":0.54677}],"urls":["https://go.dev/cl/759940","https://go.dev/issue/78566","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4986","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36754","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:50336","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54552","https://access.redhat.com/errata/RHSA-2026:54555","https://access.redhat.com/errata/RHSA-2026:54583","https://access.redhat.com/errata/RHSA-2026:54602","https://access.redhat.com/errata/RHSA-2026:54883","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57401","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57487","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:57914","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:62406","https://access.redhat.com/errata/RHSA-2026:62407","https://access.redhat.com/errata/RHSA-2026:62753","https://access.redhat.com/errata/RHSA-2026:62754","https://access.redhat.com/errata/RHSA-2026:62803","https://access.redhat.com/errata/RHSA-2026:63022","https://access.redhat.com/errata/RHSA-2026:65116","https://access.redhat.com/errata/RHSA-2026:65117","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65335","https://access.redhat.com/errata/RHSA-2026:65336","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:65895","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66327","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:67974","https://access.redhat.com/errata/RHSA-2026:67975","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:68527","https://access.redhat.com/security/cve/CVE-2026-39820","https://bugzilla.redhat.com/show_bug.cgi?id=2467820","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39820","description":"Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4918","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4918","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"risk":0.58575,"urls":["https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/761581","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."},"relatedVulnerabilities":[{"id":"CVE-2026-33814","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33814","cwe":"CWE-835","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-33814","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-33814","date":"2026-10-08","epss":0.00781,"percentile":0.54602}],"urls":["https://go.dev/cl/761581","https://go.dev/cl/761640","https://go.dev/issue/78476","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4918","https://access.redhat.com/errata/RHSA-2026:22112","https://access.redhat.com/errata/RHSA-2026:22120","https://access.redhat.com/errata/RHSA-2026:22121","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:33120","https://access.redhat.com/errata/RHSA-2026:33123","https://access.redhat.com/errata/RHSA-2026:33142","https://access.redhat.com/errata/RHSA-2026:33150","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:56854","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57367","https://access.redhat.com/errata/RHSA-2026:57408","https://access.redhat.com/errata/RHSA-2026:57545","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:60023","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60441","https://access.redhat.com/errata/RHSA-2026:60442","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60447","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60478","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:60668","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62410","https://access.redhat.com/errata/RHSA-2026:62550","https://access.redhat.com/errata/RHSA-2026:62551","https://access.redhat.com/errata/RHSA-2026:63046","https://access.redhat.com/errata/RHSA-2026:63047","https://access.redhat.com/errata/RHSA-2026:63048","https://access.redhat.com/errata/RHSA-2026:63050","https://access.redhat.com/errata/RHSA-2026:63091","https://access.redhat.com/errata/RHSA-2026:63096","https://access.redhat.com/errata/RHSA-2026:63097","https://access.redhat.com/errata/RHSA-2026:63103","https://access.redhat.com/errata/RHSA-2026:63104","https://access.redhat.com/errata/RHSA-2026:63636","https://access.redhat.com/errata/RHSA-2026:63637","https://access.redhat.com/errata/RHSA-2026:63639","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/security/cve/CVE-2026-33814","https://bugzilla.redhat.com/show_bug.cgi?id=2467815","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33814","description":"When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-rm3j-f69w-wqmq","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-rm3j-f69w-wqmq","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39834","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39834","date":"2026-10-08","epss":0.00637,"percentile":0.48909}],"risk":0.576485,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39834","https://go.dev/cl/781663","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5020"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-rm3j-f69w-wqmq","description":"golang.org/x/crypto vulnerable to infinite loop on large channel writes"},"relatedVulnerabilities":[{"id":"CVE-2026-39834","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39834","cwe":"CWE-190","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39834","date":"2026-10-08","epss":0.00637,"percentile":0.48909}],"urls":["https://go.dev/cl/781663","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5020"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39834","description":"When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-vgwf-h737-ff37","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-vgwf-h737-ff37","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39830","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39830","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39830","date":"2026-10-08","epss":0.00621,"percentile":0.48178}],"risk":0.5620050000000001,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39830","https://go.dev/cl/781640","https://go.dev/cl/781664","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5017","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/security/cve/CVE-2026-39830","https://bugzilla.redhat.com/show_bug.cgi?id=2480684","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-vgwf-h737-ff37","description":"golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses"},"relatedVulnerabilities":[{"id":"CVE-2026-39830","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39830","cwe":"CWE-119","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39830","cwe":"CWE-772","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39830","date":"2026-10-08","epss":0.00621,"percentile":0.48178}],"urls":["https://go.dev/cl/781640","https://go.dev/cl/781664","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5017","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39830","https://bugzilla.redhat.com/show_bug.cgi?id=2480684","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39830","description":"A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-31879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2021-31879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"risk":0.5519999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-31879"},"relatedVulnerabilities":[{"id":"CVE-2021-31879","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","metrics":{"baseScore":5.8,"impactScore":5,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-31879","cwe":"CWE-601","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-31879","date":"2026-10-08","epss":0.01104,"percentile":0.64746}],"urls":["https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html","https://security.netapp.com/advisory/ntap-20210618-0002/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-31879","description":"GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5026","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5026","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"risk":0.5432199999999999,"urls":["https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/767220","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error.\n\nThis behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."},"relatedVulnerabilities":[{"id":"CVE-2026-39821","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":8.2,"impactScore":5.8,"exploitabilityScore":1.8},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","metrics":{"baseScore":9.6,"impactScore":5.8,"exploitabilityScore":3.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-39821","cwe":"CWE-1289","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39821","date":"2026-10-08","epss":0.00692,"percentile":0.51378}],"urls":["https://go.dev/cl/767220","https://go.dev/issue/78760","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://pkg.go.dev/vuln/GO-2026-5026","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:30853","https://access.redhat.com/errata/RHSA-2026:30854","https://access.redhat.com/errata/RHSA-2026:30855","https://access.redhat.com/errata/RHSA-2026:33155","https://access.redhat.com/errata/RHSA-2026:33160","https://access.redhat.com/errata/RHSA-2026:33163","https://access.redhat.com/errata/RHSA-2026:33173","https://access.redhat.com/errata/RHSA-2026:33183","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:34342","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:34364","https://access.redhat.com/errata/RHSA-2026:34789","https://access.redhat.com/errata/RHSA-2026:35826","https://access.redhat.com/errata/RHSA-2026:35827","https://access.redhat.com/errata/RHSA-2026:35828","https://access.redhat.com/errata/RHSA-2026:35829","https://access.redhat.com/errata/RHSA-2026:35830","https://access.redhat.com/errata/RHSA-2026:35831","https://access.redhat.com/errata/RHSA-2026:35993","https://access.redhat.com/errata/RHSA-2026:35994","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37435","https://access.redhat.com/errata/RHSA-2026:37436","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42048","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42078","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42132","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:42852","https://access.redhat.com/errata/RHSA-2026:43038","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:44624","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:50300","https://access.redhat.com/errata/RHSA-2026:50843","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51112","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:51194","https://access.redhat.com/errata/RHSA-2026:51341","https://access.redhat.com/errata/RHSA-2026:52826","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54274","https://access.redhat.com/errata/RHSA-2026:54283","https://access.redhat.com/errata/RHSA-2026:54284","https://access.redhat.com/errata/RHSA-2026:54285","https://access.redhat.com/errata/RHSA-2026:54286","https://access.redhat.com/errata/RHSA-2026:54287","https://access.redhat.com/errata/RHSA-2026:54395","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54580","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56143","https://access.redhat.com/errata/RHSA-2026:56223","https://access.redhat.com/errata/RHSA-2026:56340","https://access.redhat.com/errata/RHSA-2026:56431","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57541","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:57845","https://access.redhat.com/errata/RHSA-2026:59546","https://access.redhat.com/errata/RHSA-2026:59549","https://access.redhat.com/errata/RHSA-2026:59562","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61245","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:62549","https://access.redhat.com/errata/RHSA-2026:63134","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65153","https://access.redhat.com/errata/RHSA-2026:65359","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65851","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66350","https://access.redhat.com/errata/RHSA-2026:66432","https://access.redhat.com/errata/RHSA-2026:67149","https://access.redhat.com/errata/RHSA-2026:67159","https://access.redhat.com/errata/RHSA-2026:67160","https://access.redhat.com/errata/RHSA-2026:67287","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:67517","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/security/cve/CVE-2026-39821","https://bugzilla.redhat.com/show_bug.cgi?id=2480756","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39821","description":"The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\"."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-x527-x647-q7gg","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-x527-x647-q7gg","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"impactScore":6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46595","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-46595","cwe":"CWE-303","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46595","date":"2026-10-08","epss":0.00503,"percentile":0.41132}],"risk":0.47785,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2024-45337","https://nvd.nist.gov/vuln/detail/CVE-2026-46595","https://go.dev/cl/781642","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5023","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/security/cve/CVE-2026-46595","https://bugzilla.redhat.com/show_bug.cgi?id=2480689","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:40945"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-x527-x647-q7gg","description":"golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement"},"relatedVulnerabilities":[{"id":"CVE-2026-46595","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.1,"impactScore":5.5,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","metrics":{"baseScore":10,"impactScore":6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46595","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-46595","cwe":"CWE-303","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-46595","date":"2026-10-08","epss":0.00503,"percentile":0.41132}],"urls":["https://go.dev/cl/781642","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5023","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:30650","https://access.redhat.com/errata/RHSA-2026:30651","https://access.redhat.com/errata/RHSA-2026:33524","https://access.redhat.com/errata/RHSA-2026:33531","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:37275","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-46595","https://bugzilla.redhat.com/show_bug.cgi?id=2480689","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46595","description":"Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.43.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4116","versionConstraint":"<0.43.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4116","fix":{"state":"fixed","versions":["0.43.0"],"available":[{"date":"2025-10-08","kind":"release","version":"0.43.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47913","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47913","date":"2026-10-08","epss":0.00623,"percentile":0.48255}],"risk":0.46725000000000005,"urls":["https://go.dev/issue/75178","https://github.com/advisories/GHSA-56w8-48fp-6mgv"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/700295","description":"SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process."},"relatedVulnerabilities":[{"id":"CVE-2025-47913","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47913","cwe":"CWE-617","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-47913","date":"2026-10-08","epss":0.00623,"percentile":0.48255}],"urls":["https://github.com/advisories/GHSA-56w8-48fp-6mgv","https://go.dev/cl/700295","https://go.dev/issue/75178","https://pkg.go.dev/vuln/GO-2025-4116"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47913","description":"SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-w879-237q-wc7r","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-w879-237q-wc7r","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39829","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39829","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39829","date":"2026-10-08","epss":0.00623,"percentile":0.48242}],"risk":0.46725000000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39829","https://go.dev/cl/781641","https://go.dev/cl/781661","https://go.dev/issue/79565","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5018","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/security/cve/CVE-2026-39829","https://bugzilla.redhat.com/show_bug.cgi?id=2480681","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40119","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41055"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-w879-237q-wc7r","description":"golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-39829","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39829","cwe":"CWE-347","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39829","cwe":"CWE-1284","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39829","date":"2026-10-08","epss":0.00623,"percentile":0.48242}],"urls":["https://go.dev/cl/781641","https://go.dev/cl/781661","https://go.dev/issue/79565","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5018","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:35833","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36820","https://access.redhat.com/errata/RHSA-2026:36883","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:48693","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54400","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57365","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60446","https://access.redhat.com/errata/RHSA-2026:60454","https://access.redhat.com/errata/RHSA-2026:60477","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65964","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:67450","https://access.redhat.com/security/cve/CVE-2026-39829","https://bugzilla.redhat.com/show_bug.cgi?id=2480681","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39829","description":"The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4870","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4870","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"risk":0.46575,"urls":["https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763767","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service.\n\nThis only affects TLS 1.3."},"relatedVulnerabilities":[{"id":"CVE-2026-32283","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32283","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-32283","cwe":"CWE-764","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32283","date":"2026-10-08","epss":0.00621,"percentile":0.48175}],"urls":["https://go.dev/cl/763767","https://go.dev/issue/78334","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4870","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11704","https://access.redhat.com/errata/RHSA-2026:11711","https://access.redhat.com/errata/RHSA-2026:11712","https://access.redhat.com/errata/RHSA-2026:11863","https://access.redhat.com/errata/RHSA-2026:11881","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16102","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17075","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19126","https://access.redhat.com/errata/RHSA-2026:19132","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19134","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19136","https://access.redhat.com/errata/RHSA-2026:19137","https://access.redhat.com/errata/RHSA-2026:19139","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19156","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19351","https://access.redhat.com/errata/RHSA-2026:19352","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19369","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22423","https://access.redhat.com/errata/RHSA-2026:22450","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22714","https://access.redhat.com/errata/RHSA-2026:22937","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23228","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55898","https://access.redhat.com/errata/RHSA-2026:55900","https://access.redhat.com/errata/RHSA-2026:55901","https://access.redhat.com/errata/RHSA-2026:55902","https://access.redhat.com/errata/RHSA-2026:55903","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57801","https://access.redhat.com/errata/RHSA-2026:57802","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:65343","https://access.redhat.com/errata/RHSA-2026:65514","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66084","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:66523","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:7291","https://access.redhat.com/errata/RHSA-2026:7385","https://access.redhat.com/security/cve/CVE-2026-32283","https://bugzilla.redhat.com/show_bug.cgi?id=2456338","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32283","description":"If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4971","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4971","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"risk":0.46499999999999997,"urls":["https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://go.dev/cl/775320"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79006","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."},"relatedVulnerabilities":[{"id":"CVE-2026-39836","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39836","cwe":"CWE-476","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39836","date":"2026-10-08","epss":0.0062,"percentile":0.48083}],"urls":["https://go.dev/cl/775320","https://go.dev/issue/79006","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4971"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39836","description":"The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0)."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-q4h4-gmj2-qvw2","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-q4h4-gmj2-qvw2","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46597","cwe":"CWE-704","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-46597","date":"2026-10-08","epss":0.0062,"percentile":0.48082}],"risk":0.46499999999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46597","https://go.dev/cl/781620","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5013"],"severity":"High","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-q4h4-gmj2-qvw2","description":"golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic"},"relatedVulnerabilities":[{"id":"CVE-2026-46597","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46597","cwe":"CWE-704","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-46597","date":"2026-10-08","epss":0.0062,"percentile":0.48082}],"urls":["https://go.dev/cl/781620","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5013"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46597","description":"An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4947","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4947","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"risk":0.46125000000000005,"urls":["https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758320","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."},"relatedVulnerabilities":[{"id":"CVE-2026-32280","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"cve":"CVE-2026-32280","cwe":"CWE-770","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-32280","date":"2026-10-08","epss":0.00615,"percentile":0.47829}],"urls":["https://go.dev/cl/758320","https://go.dev/issue/78282","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4947","https://access.redhat.com/errata/RHSA-2026:10217","https://access.redhat.com/errata/RHSA-2026:10219","https://access.redhat.com/errata/RHSA-2026:10704","https://access.redhat.com/errata/RHSA-2026:11507","https://access.redhat.com/errata/RHSA-2026:11514","https://access.redhat.com/errata/RHSA-2026:11688","https://access.redhat.com/errata/RHSA-2026:13545","https://access.redhat.com/errata/RHSA-2026:13791","https://access.redhat.com/errata/RHSA-2026:13826","https://access.redhat.com/errata/RHSA-2026:13829","https://access.redhat.com/errata/RHSA-2026:14020","https://access.redhat.com/errata/RHSA-2026:14162","https://access.redhat.com/errata/RHSA-2026:14200","https://access.redhat.com/errata/RHSA-2026:14391","https://access.redhat.com/errata/RHSA-2026:15980","https://access.redhat.com/errata/RHSA-2026:16021","https://access.redhat.com/errata/RHSA-2026:16024","https://access.redhat.com/errata/RHSA-2026:16101","https://access.redhat.com/errata/RHSA-2026:16476","https://access.redhat.com/errata/RHSA-2026:16477","https://access.redhat.com/errata/RHSA-2026:16505","https://access.redhat.com/errata/RHSA-2026:16508","https://access.redhat.com/errata/RHSA-2026:16532","https://access.redhat.com/errata/RHSA-2026:16534","https://access.redhat.com/errata/RHSA-2026:16535","https://access.redhat.com/errata/RHSA-2026:16537","https://access.redhat.com/errata/RHSA-2026:16542","https://access.redhat.com/errata/RHSA-2026:16874","https://access.redhat.com/errata/RHSA-2026:16875","https://access.redhat.com/errata/RHSA-2026:17084","https://access.redhat.com/errata/RHSA-2026:17287","https://access.redhat.com/errata/RHSA-2026:18027","https://access.redhat.com/errata/RHSA-2026:18032","https://access.redhat.com/errata/RHSA-2026:19133","https://access.redhat.com/errata/RHSA-2026:19135","https://access.redhat.com/errata/RHSA-2026:19144","https://access.redhat.com/errata/RHSA-2026:19350","https://access.redhat.com/errata/RHSA-2026:19353","https://access.redhat.com/errata/RHSA-2026:19375","https://access.redhat.com/errata/RHSA-2026:19450","https://access.redhat.com/errata/RHSA-2026:19550","https://access.redhat.com/errata/RHSA-2026:19634","https://access.redhat.com/errata/RHSA-2026:19714","https://access.redhat.com/errata/RHSA-2026:19715","https://access.redhat.com/errata/RHSA-2026:19719","https://access.redhat.com/errata/RHSA-2026:19720","https://access.redhat.com/errata/RHSA-2026:19721","https://access.redhat.com/errata/RHSA-2026:19722","https://access.redhat.com/errata/RHSA-2026:19750","https://access.redhat.com/errata/RHSA-2026:19839","https://access.redhat.com/errata/RHSA-2026:20556","https://access.redhat.com/errata/RHSA-2026:20569","https://access.redhat.com/errata/RHSA-2026:20570","https://access.redhat.com/errata/RHSA-2026:20571","https://access.redhat.com/errata/RHSA-2026:20607","https://access.redhat.com/errata/RHSA-2026:20608","https://access.redhat.com/errata/RHSA-2026:20609","https://access.redhat.com/errata/RHSA-2026:20889","https://access.redhat.com/errata/RHSA-2026:21017","https://access.redhat.com/errata/RHSA-2026:21338","https://access.redhat.com/errata/RHSA-2026:21655","https://access.redhat.com/errata/RHSA-2026:21769","https://access.redhat.com/errata/RHSA-2026:21772","https://access.redhat.com/errata/RHSA-2026:22130","https://access.redhat.com/errata/RHSA-2026:22141","https://access.redhat.com/errata/RHSA-2026:22258","https://access.redhat.com/errata/RHSA-2026:22260","https://access.redhat.com/errata/RHSA-2026:22268","https://access.redhat.com/errata/RHSA-2026:22309","https://access.redhat.com/errata/RHSA-2026:22347","https://access.redhat.com/errata/RHSA-2026:22415","https://access.redhat.com/errata/RHSA-2026:22422","https://access.redhat.com/errata/RHSA-2026:22465","https://access.redhat.com/errata/RHSA-2026:22485","https://access.redhat.com/errata/RHSA-2026:22709","https://access.redhat.com/errata/RHSA-2026:22713","https://access.redhat.com/errata/RHSA-2026:22840","https://access.redhat.com/errata/RHSA-2026:22862","https://access.redhat.com/errata/RHSA-2026:22958","https://access.redhat.com/errata/RHSA-2026:22959","https://access.redhat.com/errata/RHSA-2026:22960","https://access.redhat.com/errata/RHSA-2026:22961","https://access.redhat.com/errata/RHSA-2026:22962","https://access.redhat.com/errata/RHSA-2026:23102","https://access.redhat.com/errata/RHSA-2026:23103","https://access.redhat.com/errata/RHSA-2026:23244","https://access.redhat.com/errata/RHSA-2026:23345","https://access.redhat.com/errata/RHSA-2026:23361","https://access.redhat.com/errata/RHSA-2026:24337","https://access.redhat.com/errata/RHSA-2026:24359","https://access.redhat.com/errata/RHSA-2026:24470","https://access.redhat.com/errata/RHSA-2026:24478","https://access.redhat.com/errata/RHSA-2026:24716","https://access.redhat.com/errata/RHSA-2026:24761","https://access.redhat.com/errata/RHSA-2026:24762","https://access.redhat.com/errata/RHSA-2026:24853","https://access.redhat.com/errata/RHSA-2026:24977","https://access.redhat.com/errata/RHSA-2026:25089","https://access.redhat.com/errata/RHSA-2026:25127","https://access.redhat.com/errata/RHSA-2026:25180","https://access.redhat.com/errata/RHSA-2026:25248","https://access.redhat.com/errata/RHSA-2026:25250","https://access.redhat.com/errata/RHSA-2026:25251","https://access.redhat.com/errata/RHSA-2026:25252","https://access.redhat.com/errata/RHSA-2026:25253","https://access.redhat.com/errata/RHSA-2026:26447","https://access.redhat.com/errata/RHSA-2026:26568","https://access.redhat.com/errata/RHSA-2026:26571","https://access.redhat.com/errata/RHSA-2026:26585","https://access.redhat.com/errata/RHSA-2026:26636","https://access.redhat.com/errata/RHSA-2026:27076","https://access.redhat.com/errata/RHSA-2026:28038","https://access.redhat.com/errata/RHSA-2026:28047","https://access.redhat.com/errata/RHSA-2026:28074","https://access.redhat.com/errata/RHSA-2026:28196","https://access.redhat.com/errata/RHSA-2026:28198","https://access.redhat.com/errata/RHSA-2026:28441","https://access.redhat.com/errata/RHSA-2026:28886","https://access.redhat.com/errata/RHSA-2026:28961","https://access.redhat.com/errata/RHSA-2026:29035","https://access.redhat.com/errata/RHSA-2026:29195","https://access.redhat.com/errata/RHSA-2026:29455","https://access.redhat.com/errata/RHSA-2026:29702","https://access.redhat.com/errata/RHSA-2026:29703","https://access.redhat.com/errata/RHSA-2026:29854","https://access.redhat.com/errata/RHSA-2026:33722","https://access.redhat.com/errata/RHSA-2026:34097","https://access.redhat.com/errata/RHSA-2026:34192","https://access.redhat.com/errata/RHSA-2026:34196","https://access.redhat.com/errata/RHSA-2026:34197","https://access.redhat.com/errata/RHSA-2026:34365","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:39810","https://access.redhat.com/errata/RHSA-2026:39894","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41928","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:47712","https://access.redhat.com/errata/RHSA-2026:47714","https://access.redhat.com/errata/RHSA-2026:47716","https://access.redhat.com/errata/RHSA-2026:47719","https://access.redhat.com/errata/RHSA-2026:47721","https://access.redhat.com/errata/RHSA-2026:47722","https://access.redhat.com/errata/RHSA-2026:47910","https://access.redhat.com/errata/RHSA-2026:47952","https://access.redhat.com/errata/RHSA-2026:48036","https://access.redhat.com/errata/RHSA-2026:48790","https://access.redhat.com/errata/RHSA-2026:49509","https://access.redhat.com/errata/RHSA-2026:49526","https://access.redhat.com/errata/RHSA-2026:49600","https://access.redhat.com/errata/RHSA-2026:49838","https://access.redhat.com/errata/RHSA-2026:49944","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51288","https://access.redhat.com/errata/RHSA-2026:54191","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:56785","https://access.redhat.com/errata/RHSA-2026:56789","https://access.redhat.com/errata/RHSA-2026:56852","https://access.redhat.com/errata/RHSA-2026:56855","https://access.redhat.com/errata/RHSA-2026:56910","https://access.redhat.com/errata/RHSA-2026:56912","https://access.redhat.com/errata/RHSA-2026:56913","https://access.redhat.com/errata/RHSA-2026:57409","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:59830","https://access.redhat.com/errata/RHSA-2026:59833","https://access.redhat.com/errata/RHSA-2026:59834","https://access.redhat.com/errata/RHSA-2026:60018","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:61685","https://access.redhat.com/errata/RHSA-2026:61906","https://access.redhat.com/errata/RHSA-2026:61907","https://access.redhat.com/errata/RHSA-2026:65534","https://access.redhat.com/errata/RHSA-2026:65838","https://access.redhat.com/errata/RHSA-2026:65886","https://access.redhat.com/errata/RHSA-2026:66401","https://access.redhat.com/errata/RHSA-2026:67319","https://access.redhat.com/errata/RHSA-2026:68504","https://access.redhat.com/errata/RHSA-2026:9385","https://access.redhat.com/security/cve/CVE-2026-32280","https://bugzilla.redhat.com/show_bug.cgi?id=2456339","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32280","description":"During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5037","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5037","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"risk":0.4432500000000001,"urls":["https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/783621","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname.\n\nWith a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."},"relatedVulnerabilities":[{"id":"CVE-2026-27145","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27145","cwe":"CWE-606","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-27145","date":"2026-10-08","epss":0.00591,"percentile":0.46588}],"urls":["https://go.dev/cl/783621","https://go.dev/issue/79694","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5037","https://access.redhat.com/errata/RHSA-2026:23262","https://access.redhat.com/errata/RHSA-2026:23264","https://access.redhat.com/errata/RHSA-2026:29980","https://access.redhat.com/errata/RHSA-2026:29981","https://access.redhat.com/errata/RHSA-2026:33574","https://access.redhat.com/errata/RHSA-2026:34357","https://access.redhat.com/errata/RHSA-2026:34359","https://access.redhat.com/errata/RHSA-2026:35832","https://access.redhat.com/errata/RHSA-2026:36317","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:38995","https://access.redhat.com/errata/RHSA-2026:39005","https://access.redhat.com/errata/RHSA-2026:39573","https://access.redhat.com/errata/RHSA-2026:39879","https://access.redhat.com/errata/RHSA-2026:41030","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41930","https://access.redhat.com/errata/RHSA-2026:42043","https://access.redhat.com/errata/RHSA-2026:42047","https://access.redhat.com/errata/RHSA-2026:42049","https://access.redhat.com/errata/RHSA-2026:42050","https://access.redhat.com/errata/RHSA-2026:42051","https://access.redhat.com/errata/RHSA-2026:42079","https://access.redhat.com/errata/RHSA-2026:42080","https://access.redhat.com/errata/RHSA-2026:42082","https://access.redhat.com/errata/RHSA-2026:42142","https://access.redhat.com/errata/RHSA-2026:42150","https://access.redhat.com/errata/RHSA-2026:42151","https://access.redhat.com/errata/RHSA-2026:42240","https://access.redhat.com/errata/RHSA-2026:42644","https://access.redhat.com/errata/RHSA-2026:42946","https://access.redhat.com/errata/RHSA-2026:44622","https://access.redhat.com/errata/RHSA-2026:46394","https://access.redhat.com/errata/RHSA-2026:46395","https://access.redhat.com/errata/RHSA-2026:47149","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47737","https://access.redhat.com/errata/RHSA-2026:49702","https://access.redhat.com/errata/RHSA-2026:49703","https://access.redhat.com/errata/RHSA-2026:49705","https://access.redhat.com/errata/RHSA-2026:49712","https://access.redhat.com/errata/RHSA-2026:49729","https://access.redhat.com/errata/RHSA-2026:49744","https://access.redhat.com/errata/RHSA-2026:49765","https://access.redhat.com/errata/RHSA-2026:49770","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:50319","https://access.redhat.com/errata/RHSA-2026:51057","https://access.redhat.com/errata/RHSA-2026:51187","https://access.redhat.com/errata/RHSA-2026:52946","https://access.redhat.com/errata/RHSA-2026:53374","https://access.redhat.com/errata/RHSA-2026:53412","https://access.redhat.com/errata/RHSA-2026:53413","https://access.redhat.com/errata/RHSA-2026:53415","https://access.redhat.com/errata/RHSA-2026:53416","https://access.redhat.com/errata/RHSA-2026:53530","https://access.redhat.com/errata/RHSA-2026:54168","https://access.redhat.com/errata/RHSA-2026:54401","https://access.redhat.com/errata/RHSA-2026:54427","https://access.redhat.com/errata/RHSA-2026:54432","https://access.redhat.com/errata/RHSA-2026:54435","https://access.redhat.com/errata/RHSA-2026:54441","https://access.redhat.com/errata/RHSA-2026:54500","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:54603","https://access.redhat.com/errata/RHSA-2026:54757","https://access.redhat.com/errata/RHSA-2026:55899","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:57482","https://access.redhat.com/errata/RHSA-2026:57488","https://access.redhat.com/errata/RHSA-2026:57649","https://access.redhat.com/errata/RHSA-2026:59556","https://access.redhat.com/errata/RHSA-2026:59557","https://access.redhat.com/errata/RHSA-2026:59558","https://access.redhat.com/errata/RHSA-2026:59559","https://access.redhat.com/errata/RHSA-2026:59579","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60025","https://access.redhat.com/errata/RHSA-2026:60315","https://access.redhat.com/errata/RHSA-2026:60354","https://access.redhat.com/errata/RHSA-2026:60386","https://access.redhat.com/errata/RHSA-2026:60387","https://access.redhat.com/errata/RHSA-2026:60388","https://access.redhat.com/errata/RHSA-2026:60390","https://access.redhat.com/errata/RHSA-2026:60391","https://access.redhat.com/errata/RHSA-2026:61253","https://access.redhat.com/errata/RHSA-2026:61314","https://access.redhat.com/errata/RHSA-2026:63016","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:68334","https://access.redhat.com/errata/RHSA-2026:68335","https://access.redhat.com/security/cve/CVE-2026-27145","https://bugzilla.redhat.com/show_bug.cgi?id=2484207","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27145","description":"(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-89gr-r52h-f8rx","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-89gr-r52h-f8rx","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39831","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39831","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"risk":0.440735,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39831","https://go.dev/cl/781662","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5019"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-89gr-r52h-f8rx","description":"golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed"},"relatedVulnerabilities":[{"id":"CVE-2026-39831","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39831","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39831","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"urls":["https://go.dev/cl/781662","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5019"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39831","description":"The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a \"no-touch-required\" extension in Permissions.Extensions from PublicKeyCallback."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-jppx-rxg9-jmrx","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-jppx-rxg9-jmrx","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39833","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39833","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"risk":0.440735,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39833","https://go.dev/cl/778640","https://go.dev/cl/778641","https://go.dev/issue/79436","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005"],"severity":"Critical","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-jppx-rxg9-jmrx","description":"golang.org/x/crypto doesn't enforce invoking key constraints"},"relatedVulnerabilities":[{"id":"CVE-2026-39833","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":9.1,"impactScore":5.2,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39833","cwe":"CWE-862","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39833","date":"2026-10-08","epss":0.00487,"percentile":0.39976}],"urls":["https://go.dev/cl/778642","https://go.dev/issue/79436","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39833","description":"The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4342","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4342","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"risk":0.430675,"urls":["https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/736713","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."},"relatedVulnerabilities":[{"id":"CVE-2025-61728","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61728","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61728","date":"2026-10-08","epss":0.00749,"percentile":0.53509}],"urls":["https://go.dev/cl/736713","https://go.dev/issue/77102","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4342","http://www.openwall.com/lists/oss-security/2026/01/15/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61728","description":"archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service when consuming a maliciously constructed ZIP archive."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6089","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6089","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/795540","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80205","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."},"relatedVulnerabilities":[{"id":"CVE-2026-56853","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56853","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56853","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/795540","https://go.dev/issue/80205","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6089"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56853","description":"When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6090","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6090","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"risk":0.426,"urls":["https://go.dev/cl/804261","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80528","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."},"relatedVulnerabilities":[{"id":"CVE-2026-56862","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56862","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56862","date":"2026-10-08","epss":0.00568,"percentile":0.45315}],"urls":["https://go.dev/cl/804261","https://go.dev/issue/80528","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6090"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56862","description":"Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5972","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5972","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://go.dev/cl/814980"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80405","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."},"relatedVulnerabilities":[{"id":"CVE-2026-33818","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-33818","cwe":"CWE-400","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-33818","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/814980","https://go.dev/issue/80405","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-5972"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-33818","description":"Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6088","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6088","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"risk":0.426,"urls":["https://go.dev/cl/803320","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80481","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."},"relatedVulnerabilities":[{"id":"CVE-2026-56859","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56859","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56859","date":"2026-10-08","epss":0.00568,"percentile":0.45314}],"urls":["https://go.dev/cl/803320","https://go.dev/issue/80481","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6088"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56859","description":"Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5038","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5038","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"risk":0.42,"urls":["https://go.dev/cl/774481","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79217","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-42504","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42504","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42504","date":"2026-10-08","epss":0.0056,"percentile":0.44869}],"urls":["https://go.dev/cl/774481","https://go.dev/issue/79217","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5038"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42504","description":"Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU."}]},{"artifact":{"id":"e2ab31589535b3e0","cpes":["cpe:2.3:a:patch:patch:2.7.6-7build3:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/ubuntu/patch@2.7.6-7build3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.7.6-7build3","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2018-6952","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"patch","version":"2.7.6-7build3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2018-6952","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"risk":0.40950000000000003,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2018-6952"},"relatedVulnerabilities":[{"id":"CVE-2018-6952","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2018-6952","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2018-6952","date":"2026-10-08","epss":0.0819,"percentile":0.94738}],"urls":["http://www.securityfocus.com/bid/103047","https://access.redhat.com/errata/RHSA-2019:2033","https://savannah.gnu.org/bugs/index.php?53133","https://security.gentoo.org/glsa/201904-17"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2018-6952","description":"A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6355","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6355","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"risk":0.375,"urls":["https://go.dev/cl/826524","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81317","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection.\n\nNow, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."},"relatedVulnerabilities":[{"id":"CVE-2026-56855","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56855","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56855","date":"2026-10-08","epss":0.005,"percentile":0.4091}],"urls":["https://go.dev/cl/826524","https://go.dev/issue/81317","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6355"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56855","description":"Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11940","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11940","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"risk":0.375,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11940"},"relatedVulnerabilities":[{"id":"CVE-2026-11940","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11940","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11940","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11940","date":"2026-10-08","epss":0.0075,"percentile":0.53541}],"urls":["https://github.com/python/cpython/commit/0f852b3f07dd8e71e40326a51c02afbf16a42cc5","https://github.com/python/cpython/commit/27dd970bf6b17ebca7c8ed486a40ab043ed7af8f","https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df","https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde","https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c","https://github.com/python/cpython/commit/be13e86f6b9788a6f4d0419dffef72cbae5865c9","https://github.com/python/cpython/commit/e5fdbd8d5aa923bd9111b112ea73bd6ec7c47877","https://github.com/python/cpython/issues/151558","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/LD6QIISNQFQYOIEPJNEUIPV7S3V76FZH/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11940","description":"tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.  \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.  \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-17084","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-17084","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"risk":0.367,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-17084"},"relatedVulnerabilities":[{"id":"CVE-2026-17084","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-17084","cwe":"CWE-436","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-17084","date":"2026-10-08","epss":0.00734,"percentile":0.52989}],"urls":["https://github.com/python/cpython/commit/1e54caa096678a38afcabecabb1ff72400dd6bae","https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7","https://github.com/python/cpython/commit/69f92ebaec681e9149dfd70fd02d4ed52d2a6296","https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc","https://github.com/python/cpython/commit/c016c2535b74227fddf2cf7334dbfead6c930214","https://github.com/python/cpython/commit/c28b121a4f0b975937c8b5a1b4934bb361d84296","https://github.com/python/cpython/commit/c42790b34f634051750e5da340d17c7da19e4784","https://github.com/python/cpython/commit/d397a4979cfc80a8cd6c73838aa10e9c8cf5ef72","https://github.com/python/cpython/issues/155292","https://github.com/python/cpython/pull/155293","https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/","http://www.openwall.com/lists/oss-security/2026/08/18/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084","description":"The \"stringprep\" module didn't process characters from RFC 3454 tables \nB.2 or B.3 correctly: the latest Unicode codepoint attributes were used \ninstead of the specified Unicode 3.2.0. This behavior would cause \nmismatches when processing domain names using IDNA 2003 (the \"idna\" \ncodec) and the in_table_b2() function of the \"stringprep\" module. This \nonly affects domain names containing characters that were not previously\n registered or had their Unicode attributes such as case-folding \nbehavior updated since Unicode 3.2.0."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-11972","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11972","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"risk":0.3575,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11972"},"relatedVulnerabilities":[{"id":"CVE-2026-11972","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11972","cwe":"CWE-252","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-606","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-11972","cwe":"CWE-770","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-11972","date":"2026-10-08","epss":0.00715,"percentile":0.52297}],"urls":["https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9","https://github.com/python/cpython/commit/4ce6bf7c8aa7725828a38981c306f214c1f29365","https://github.com/python/cpython/commit/7f0dc59c9a70f8f3b4da33d7c4a2ba552a7acc21","https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec","https://github.com/python/cpython/commit/eb63c0f94dfcbea7fda8eab6213818e134d67192","https://github.com/python/cpython/commit/f50bf13566189c8d0ce5a814f33eff3d89951896","https://github.com/python/cpython/commit/f5e2776ff0383a902c12acf2b703e7e951fc8438","https://github.com/python/cpython/issues/151981","https://github.com/python/cpython/pull/151982","https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11972","description":"When using the \"tarfile\" module with a file opened in \"streaming mode\" (mode=\"r|\") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4155","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4155","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"risk":0.34275,"urls":["https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/725920","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."},"relatedVulnerabilities":[{"id":"CVE-2025-61729","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61729","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61729","date":"2026-10-08","epss":0.00457,"percentile":0.37641}],"urls":["https://go.dev/cl/725920","https://go.dev/issue/76445","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4155"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61729","description":"Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error string is constructed by repeated string concatenation, leading to quadratic runtime. Therefore, a certificate provided by a malicious actor can result in excessive resource consumption."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-78mq-xcr3-xm33","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-78mq-xcr3-xm33","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39835","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39835","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39835","date":"2026-10-08","epss":0.00662,"percentile":0.50108}],"risk":0.34093,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39835","https://go.dev/cl/781660","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5015","https://access.redhat.com/security/cve/CVE-2026-39835","https://bugzilla.redhat.com/show_bug.cgi?id=2480680","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:51036","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-78mq-xcr3-xm33","description":"golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow"},"relatedVulnerabilities":[{"id":"CVE-2026-39835","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39835","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39835","cwe":"CWE-476","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39835","date":"2026-10-08","epss":0.00662,"percentile":0.50108}],"urls":["https://go.dev/cl/781660","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5015","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36199","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:37072","https://access.redhat.com/errata/RHSA-2026:37123","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37410","https://access.redhat.com/errata/RHSA-2026:38504","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:47949","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51036","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54525","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:59593","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:62260","https://access.redhat.com/errata/RHSA-2026:65126","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-39835","https://bugzilla.redhat.com/show_bug.cgi?id=2480680","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39835","description":"SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.55.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6303","versionConstraint":"<0.55.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6303","fix":{"state":"fixed","versions":["0.55.0"],"available":[{"date":"2026-08-11","kind":"release","version":"0.55.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56854","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56854","date":"2026-10-08","epss":0.00437,"percentile":0.36015}],"risk":0.32775,"urls":["https://go.dev/cl/797040"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80213","description":"The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback."},"relatedVulnerabilities":[{"id":"CVE-2026-56854","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56854","cwe":"CWE-863","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56854","date":"2026-10-08","epss":0.00437,"percentile":0.36015}],"urls":["https://go.dev/cl/797040","https://go.dev/issue/80213","https://pkg.go.dev/vuln/GO-2026-6303"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56854","description":"The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.56.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6354","versionConstraint":"<0.56.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6354","fix":{"state":"fixed","versions":["0.56.0"],"available":[{"date":"2026-09-02","kind":"release","version":"0.56.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"risk":0.32325,"urls":["https://go.dev/cl/826504","https://groups.google.com/g/golang-announce/c/1y3fb2np35U"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/81316","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection.\n\nNow, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."},"relatedVulnerabilities":[{"id":"CVE-2026-78662","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78662","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-78662","date":"2026-10-08","epss":0.00431,"percentile":0.3535}],"urls":["https://go.dev/cl/826504","https://go.dev/issue/81316","https://groups.google.com/g/golang-announce/c/1y3fb2np35U","https://pkg.go.dev/vuln/GO-2026-6354"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78662","description":"Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-87910","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-87910","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"risk":0.3215,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-87910"},"relatedVulnerabilities":[{"id":"CVE-2026-87910","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.7},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-87910","cwe":"CWE-22","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-87910","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-87910","date":"2026-10-08","epss":0.00643,"percentile":0.49252}],"urls":["https://github.com/python/cpython/commit/2eb0c2f1dc71847731b6ab30aebefd058d482a7f","https://github.com/python/cpython/commit/3105a3498aaf681ce128cf5baf83c2e5574267c5","https://github.com/python/cpython/commit/764fd0af8d9e19d3684a58d2e58bf770f0605036","https://github.com/python/cpython/commit/9c17bace90f88dfba6d0e2fe23c8e7ae35f83955","https://github.com/python/cpython/commit/a4919937a4e1e69a0d178909c6f20557eca5d1d0","https://github.com/python/cpython/commit/c1f106d240c4ffcb3608ed0a20e8aba6c865f6d3","https://github.com/python/cpython/commit/d9565e54b1fc6d63c5be9afd58114499128fa57b","https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2","https://github.com/python/cpython/issues/157265","https://github.com/python/cpython/pull/157266","https://mail.python.org/archives/list/security-announce@python.org/thread/57TBTLL2W6APMZR3A25B2YV7GL3EPTDJ/","http://www.openwall.com/lists/oss-security/2026/09/11/8"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910","description":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2024-10524","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10524","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"risk":0.32130000000000003,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10524"},"relatedVulnerabilities":[{"id":"CVE-2024-10524","cvss":[{"type":"Secondary","source":"reefs@jfrog.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":6.5,"impactScore":3.8,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10524","cwe":"CWE-918","type":"Secondary","source":"reefs@jfrog.com"}],"epss":[{"cve":"CVE-2024-10524","date":"2026-10-08","epss":0.01071,"percentile":0.63827}],"urls":["https://git.savannah.gnu.org/cgit/wget.git/commit/?id=c419542d956a2607bbce5df64b9d378a8588d778","https://jfrog.com/blog/cve-2024-10524-wget-zero-day-vulnerability/","https://seclists.org/oss-sec/2024/q4/107","http://www.openwall.com/lists/oss-security/2024/11/18/6","https://security.netapp.com/advisory/ntap-20250321-0007/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10524","description":"Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host."}]},{"artifact":{"id":"bdd817d23e512645","cpes":["cpe:2.3:a:perl-base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl-base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl_base:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl-base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:perl:perl_base:5.38.2-3.2ubuntu0.6:*:*:*:*:*:*:*"],"name":"perl-base","purl":"pkg:deb/ubuntu/perl-base@5.38.2-3.2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=perl","type":"deb","version":"5.38.2-3.2ubuntu0.6","language":"","licenses":["Artistic","Artistic-2","Artistic-dist","BSD-3-clause","BSD-3-clause-GENERIC","BSD-3-clause-with-weird-numbering","BSD-4-clause-POWERDOG","BZIP","DONT-CHANGE-THE-GPL","Expat","FSFAP","GPL-1","GPL-1+","GPL-2","GPL-2+","GPL-3+-WITH-BISON-EXCEPTION","LGPL-2.1","REGCOMP","REGCOMP,","SDBM-PUBLIC-DOMAIN","TEXT-TABS","Unicode","ZLIB"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/perl-base/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/perl-base/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/perl-base.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.list"},{"path":"/var/lib/dpkg/info/perl-base.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.postinst"},{"path":"/var/lib/dpkg/info/perl-base.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.postrm"},{"path":"/var/lib/dpkg/info/perl-base.preinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.preinst"},{"path":"/var/lib/dpkg/info/perl-base.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/perl-base.prerm"}],"upstreams":[{"name":"perl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82560","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"perl","version":"5.38.2-3.2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82560","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"risk":0.315,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82560"},"relatedVulnerabilities":[{"id":"CVE-2026-82560","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82560","cwe":"CWE-835","type":"Secondary","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"}],"epss":[{"cve":"CVE-2026-82560","date":"2026-10-08","epss":0.0063,"percentile":0.48579}],"urls":["https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch","https://metacpan.org/release/RRA/podlators-v6.1.0/source/lib/Pod/Text.pm#L245-261","https://metacpan.org/release/RRA/podlators-v6.1.1/changes","http://www.openwall.com/lists/oss-security/2026/09/19/6"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82560","description":"Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.\n\nEach =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.\n\nFormatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-45gg-vh54-h5m9","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-45gg-vh54-h5m9","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39828","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39828","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39828","date":"2026-10-08","epss":0.00539,"percentile":0.43577}],"risk":0.30453499999999994,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39828","https://go.dev/cl/781621","https://go.dev/issue/79562","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5014","https://access.redhat.com/security/cve/CVE-2026-39828","https://bugzilla.redhat.com/show_bug.cgi?id=2480687","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40119","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:41055"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-45gg-vh54-h5m9","description":"golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions"},"relatedVulnerabilities":[{"id":"CVE-2026-39828","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":8.8,"impactScore":5.9,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":6.3,"impactScore":3.4,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39828","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2026-39828","cwe":"CWE-281","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-39828","date":"2026-10-08","epss":0.00539,"percentile":0.43577}],"urls":["https://go.dev/cl/781621","https://go.dev/issue/79562","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5014","https://access.redhat.com/errata/RHSA-2026:26546","https://access.redhat.com/errata/RHSA-2026:26547","https://access.redhat.com/errata/RHSA-2026:36105","https://access.redhat.com/errata/RHSA-2026:36167","https://access.redhat.com/errata/RHSA-2026:36207","https://access.redhat.com/errata/RHSA-2026:36319","https://access.redhat.com/errata/RHSA-2026:36625","https://access.redhat.com/errata/RHSA-2026:36648","https://access.redhat.com/errata/RHSA-2026:36651","https://access.redhat.com/errata/RHSA-2026:36796","https://access.redhat.com/errata/RHSA-2026:36797","https://access.redhat.com/errata/RHSA-2026:36808","https://access.redhat.com/errata/RHSA-2026:37268","https://access.redhat.com/errata/RHSA-2026:37271","https://access.redhat.com/errata/RHSA-2026:37272","https://access.redhat.com/errata/RHSA-2026:37278","https://access.redhat.com/errata/RHSA-2026:37286","https://access.redhat.com/errata/RHSA-2026:37296","https://access.redhat.com/errata/RHSA-2026:37387","https://access.redhat.com/errata/RHSA-2026:40118","https://access.redhat.com/errata/RHSA-2026:40262","https://access.redhat.com/errata/RHSA-2026:40945","https://access.redhat.com/errata/RHSA-2026:40969","https://access.redhat.com/errata/RHSA-2026:40972","https://access.redhat.com/errata/RHSA-2026:40974","https://access.redhat.com/errata/RHSA-2026:41019","https://access.redhat.com/errata/RHSA-2026:41031","https://access.redhat.com/errata/RHSA-2026:41036","https://access.redhat.com/errata/RHSA-2026:41055","https://access.redhat.com/errata/RHSA-2026:41066","https://access.redhat.com/errata/RHSA-2026:42146","https://access.redhat.com/errata/RHSA-2026:42796","https://access.redhat.com/errata/RHSA-2026:43052","https://access.redhat.com/errata/RHSA-2026:43692","https://access.redhat.com/errata/RHSA-2026:46885","https://access.redhat.com/errata/RHSA-2026:46903","https://access.redhat.com/errata/RHSA-2026:47735","https://access.redhat.com/errata/RHSA-2026:48151","https://access.redhat.com/errata/RHSA-2026:51033","https://access.redhat.com/errata/RHSA-2026:51038","https://access.redhat.com/errata/RHSA-2026:52857","https://access.redhat.com/errata/RHSA-2026:52910","https://access.redhat.com/errata/RHSA-2026:54531","https://access.redhat.com/errata/RHSA-2026:57191","https://access.redhat.com/errata/RHSA-2026:57194","https://access.redhat.com/errata/RHSA-2026:59467","https://access.redhat.com/errata/RHSA-2026:60520","https://access.redhat.com/errata/RHSA-2026:66022","https://access.redhat.com/errata/RHSA-2026:66521","https://access.redhat.com/security/cve/CVE-2026-39828","https://bugzilla.redhat.com/show_bug.cgi?id=2480687","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39828","description":"When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6218","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6218","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"risk":0.29975,"urls":["https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/803681","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.\n\nNow, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."},"relatedVulnerabilities":[{"id":"CVE-2026-56860","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56860","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56860","date":"2026-10-08","epss":0.0055,"percentile":0.44284}],"urls":["https://go.dev/cl/803681","https://go.dev/issue/80494","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6218"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56860","description":"Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-j5w8-q4qc-rx2x","versionConstraint":"<0.45.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-j5w8-q4qc-rx2x","fix":{"state":"fixed","versions":["0.45.0"],"available":[{"date":"2025-11-20","kind":"first-observed","version":"0.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58181","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-58181","date":"2026-10-08","epss":0.00561,"percentile":0.44933}],"risk":0.28891500000000003,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-58181","https://go.dev/cl/721961","https://go.dev/issue/76363","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4134"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-j5w8-q4qc-rx2x","description":"golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption"},"relatedVulnerabilities":[{"id":"CVE-2025-58181","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-58181","cwe":"CWE-770","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-58181","date":"2026-10-08","epss":0.00561,"percentile":0.44933}],"urls":["https://go.dev/cl/721961","https://go.dev/issue/76363","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4134"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-58181","description":"SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-12781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-12781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"risk":0.2845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-12781"},"relatedVulnerabilities":[{"id":"CVE-2025-12781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-12781","cwe":"CWE-704","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-12781","date":"2026-10-08","epss":0.00569,"percentile":0.45399}],"urls":["https://github.com/python/cpython/commit/13360efd385d1a7d0659beba03787ea3d063ef9b","https://github.com/python/cpython/commit/1be80bec7960f5ccd059e75f3dfbd45fca302947","https://github.com/python/cpython/commit/9060b4abbe475591b6230b23c2afefeff26fcca5","https://github.com/python/cpython/commit/e95e783dff443b68e8179fdb57737025bf02ba76","https://github.com/python/cpython/commit/fd17ee026fa9b67f6288cbafe374a3e479fe03a5","https://github.com/python/cpython/issues/125346","https://github.com/python/cpython/pull/141128","https://mail.python.org/archives/list/security-announce@python.org/thread/KRI7GC6S27YV5NJ4FPDALS2WI5ENAFJ6/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-12781","description":"When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the \"base64\" module the characters \"+/\" will always be accepted, regardless of the value of \"altchars\" parameter, typically used to establish an \"alternative base64 alphabet\" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.\n\n\n\n\nThis behavior can only be insecure if your application uses an alternate base64 alphabet (without \"+/\"). If your application does not use the \"altchars\" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.\n\n\n\n\nThe attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 \nalphabet they are expecting or verify that their application would not be \naffected if the b64decode() functions accepted \"+\" or \"/\" outside of altchars."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-77214","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-77214","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"risk":0.2745,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-77214"},"relatedVulnerabilities":[{"id":"CVE-2026-77214","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-77214","cwe":"CWE-125","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-77214","date":"2026-10-08","epss":0.00549,"percentile":0.44207}],"urls":["https://github.com/libexpat/libexpat/commit/13c5f63a7f1c52c2feee3b16a1134d4fb68e9ea0","https://github.com/libexpat/libexpat/pull/1393","https://www.vulncheck.com/advisories/libexpat-heap-buffer-over-read-in-xmlparse-c-via-xml-parsebuffer"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-77214","description":"libexpat before commit 13c5f63 contains a heap buffer over-read vulnerability in xmlparse.c. XML_ParseBuffer advances the parse buffer end with parser->m_bufferEnd += len using a caller-supplied length that is not validated against the allocated buffer size, so repeated XML_ParseBuffer calls move m_bufferEnd past the end of the heap allocation and subsequent parsing reads out of bounds. Reaching this path requires a parse buffer to already be present; otherwise XML_ParseBuffer returns XML_ERROR_NO_BUFFER. A buffer is present after a prior call to XML_GetBuffer, either directly (the common case) or indirectly through a prior XML_Parse call that allocates the buffer internally. The over-read discloses adjacent heap memory to the calling application, recovering heap pointers, libc function pointers, and code pointers sufficient to defeat ASLR and build further exploitation primitives."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4946","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4946","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"risk":0.26625,"urls":["https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/758061","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service.\n\nThis only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."},"relatedVulnerabilities":[{"id":"CVE-2026-32281","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32281","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32281","date":"2026-10-08","epss":0.00355,"percentile":0.27185}],"urls":["https://go.dev/cl/758061","https://go.dev/issue/78281","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4946"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32281","description":"Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, possibly causing denial of service. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-9m57-25v3-79x9","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-9m57-25v3-79x9","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46598","cwe":"CWE-129","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46598","date":"2026-10-08","epss":0.00515,"percentile":0.42036}],"risk":0.265225,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-46598","https://go.dev/cl/781360","https://go.dev/issue/79596","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-9m57-25v3-79x9","description":"golang.org/x/crypto: Invoking pathological inputs can lead to client panic"},"relatedVulnerabilities":[{"id":"CVE-2026-46598","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-46598","cwe":"CWE-129","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-46598","date":"2026-10-08","epss":0.00515,"percentile":0.42036}],"urls":["https://go.dev/cl/781360","https://go.dev/issue/79596","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-46598","description":"For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15310","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15310","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"risk":0.263,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15310"},"relatedVulnerabilities":[{"id":"CVE-2026-15310","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15310","cwe":"CWE-400","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15310","date":"2026-10-08","epss":0.00526,"percentile":0.42759}],"urls":["https://github.com/python/cpython/commit/09a2e7e6678b4f65449e7ad8f112c48f944591e2","https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8","https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89","https://github.com/python/cpython/commit/6257029de42ef89b67f3d20137de87d43e197530","https://github.com/python/cpython/commit/9d167992b59cf5e23c66b9ed742b13f5925f7d70","https://github.com/python/cpython/commit/c2bfbcdd1a11690507a10bc0998f95b8dc6b6fac","https://github.com/python/cpython/commit/dcdd406ddbfc4cb29b24c3df17cbabe21d316ce1","https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a","https://github.com/python/cpython/commit/f507e6946a3194e83e1d7b8ee6e14567175e46de","https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4","https://github.com/python/cpython/issues/156002","https://github.com/python/cpython/pull/156003","https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15310","description":"When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.45.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-f6x5-jh6r-wrfv","versionConstraint":"<0.45.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-f6x5-jh6r-wrfv","fix":{"state":"fixed","versions":["0.45.0"],"available":[{"date":"2025-11-21","kind":"first-observed","version":"0.45.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47914","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-47914","date":"2026-10-08","epss":0.0051,"percentile":0.41611}],"risk":0.26265000000000005,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2025-47914","https://go.dev/cl/721960","https://go.dev/issue/76364","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4135"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-f6x5-jh6r-wrfv","description":"golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read"},"relatedVulnerabilities":[{"id":"CVE-2025-47914","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-47914","cwe":"CWE-125","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2025-47914","date":"2026-10-08","epss":0.0051,"percentile":0.41611}],"urls":["https://go.dev/cl/721960","https://go.dev/issue/76364","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4135"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-47914","description":"SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19672","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19672","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"risk":0.261,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19672"},"relatedVulnerabilities":[{"id":"CVE-2026-19672","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.3},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19672","cwe":"CWE-22","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-19672","date":"2026-10-08","epss":0.00522,"percentile":0.42513}],"urls":["https://github.com/python/cpython/pull/156000","https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/","http://www.openwall.com/lists/oss-security/2026/08/25/10"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672","description":"The tarfile module's tar and data\n extraction filters created directories outside the destination for \nmembers whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.\n\nOnly\n empty directories are created outside the destination. Member contents \nare still extracted inside it. To return to the destination the member's\n name must contain the destination directory's own final component, so \nextraction into a secure randomised directory is not affected.\n\nThis affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-15806","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-15806","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"risk":0.232,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-15806"},"relatedVulnerabilities":[{"id":"CVE-2026-15806","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-15806","cwe":"CWE-319","type":"Secondary","source":"cna@python.org"},{"cve":"CVE-2026-15806","cwe":"CWE-522","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-15806","date":"2026-10-08","epss":0.00464,"percentile":0.38184}],"urls":["https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6","https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc","https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801","https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8","https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce","https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce","https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a","https://github.com/python/cpython/issues/155694","https://github.com/python/cpython/pull/155696","https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/","http://www.openwall.com/lists/oss-security/2026/08/18/3"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806","description":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.\n\nCredential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.\n\nUsers who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4980","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4980","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"risk":0.21811499999999998,"urls":["https://go.dev/cl/771180","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78981","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."},"relatedVulnerabilities":[{"id":"CVE-2026-39826","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39826","cwe":"CWE-116","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39826","date":"2026-10-08","epss":0.00393,"percentile":0.31319}],"urls":["https://go.dev/cl/771180","https://go.dev/issue/78981","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4980"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39826","description":"If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape any data passed into the <script> block."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19445","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19445","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"risk":0.21450000000000002,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19445"},"relatedVulnerabilities":[{"id":"CVE-2026-19445","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":9.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19445","cwe":"CWE-416","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19445","date":"2026-10-08","epss":0.00429,"percentile":0.35164}],"urls":["https://github.com/python/cpython/commit/34a53dce8174da2fceb12fe084a4def02a10053d","https://github.com/python/cpython/commit/46133cd57d309652139ada74014aca7665ac552b","https://github.com/python/cpython/commit/63fab143d94cafae71850831acfb52041ba44af7","https://github.com/python/cpython/commit/b12968cefe69ca1dcb8606c832ff73ee7dbf4ba8","https://github.com/python/cpython/commit/cd7e51e7d4563866fbaa1e2521ae69b45daf3698","https://github.com/python/cpython/commit/d8717ed01717a9641686e6e6f83f0ab8af235e2c","https://github.com/python/cpython/commit/ec44b5a3258cbda947d5e07242ee562ed05ef24b","https://github.com/python/cpython/issues/156293","https://github.com/python/cpython/pull/158504","https://mail.python.org/archives/list/security-announce@python.org/thread/QMQIUQB6WGGC3MI7I3WKQXOYOBDSPPS3/","http://www.openwall.com/lists/oss-security/2026/09/30/17"],"severity":"Critical","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19445","description":"A remote, unauthenticated TLS client can make a server crash or call\nthrough a freed pointer if its sni_callback assigns a different context to\nSSLSocket.context (the documented way to select a certificate per server\nname) and nothing else keeps the original ssl.SSLContext alive. Typical\ncases are servers that create an SSLContext per connection or replace it\nwhile connections are open; servers that wrap their listening socket with\nit are not affected.\n\n\nMitigation: keep a reference to every SSLContext that sets sni_callback for\nthe lifetime of the server. TLS clients are not affected."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4976","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4976","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"risk":0.212695,"urls":["https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/770541","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions.\n\nWhen used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function.\n\nFor example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."},"relatedVulnerabilities":[{"id":"CVE-2026-39825","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-39825","date":"2026-10-08","epss":0.00413,"percentile":0.33451}],"urls":["https://go.dev/cl/770541","https://go.dev/issue/78948","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4976"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39825","description":"ReverseProxy can forward queries containing parameters not visible to Rewrite functions. When used with a Rewrite function, or a Director function which parses query parameters, ReverseProxy sanitizes the forwarded request to remove query parameters which are not parsed by url.ParseQuery. ReverseProxy does not take ParseQuery's limit on the total number of query parameters (controlled by GODEBUG=urlmaxqueryparams=N) into account. This can permit ReverseProxy to forward a request containing a query parameter that is not visible to the Rewrite function. For example, the query \"a1=x&a2=x&...&a10000=x&hidden=y\" can forward the parameter \"hidden=y\" while hiding it from the proxy's Rewrite function."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5039","versionConstraint":"<1.25.11||>=1.26.0-0,<1.26.4 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5039","fix":{"state":"fixed","versions":["1.25.11","1.26.4"],"available":[{"date":"2026-06-02","kind":"release","version":"1.25.11"},{"date":"2026-06-02","kind":"release","version":"1.26.4"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"risk":0.21218,"urls":["https://go.dev/cl/777060","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79346","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."},"relatedVulnerabilities":[{"id":"CVE-2026-42507","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2026-42507","date":"2026-10-08","epss":0.00412,"percentile":0.33355}],"urls":["https://go.dev/cl/777060","https://go.dev/issue/79346","https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw","https://pkg.go.dev/vuln/GO-2026-5039"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42507","description":"When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15366","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"risk":0.211,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15366"},"relatedVulnerabilities":[{"id":"CVE-2025-15366","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15366","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15366","date":"2026-10-08","epss":0.00422,"percentile":0.34477}],"urls":["https://github.com/python/cpython/commit/298182272a740ce2016aee2f54acbd0bba1944c1","https://github.com/python/cpython/commit/6262704b134db2a4ba12e85ecfbd968534f28b45","https://github.com/python/cpython/commit/71926d943c05bde79bd2a866933103541d91b6a2","https://github.com/python/cpython/commit/d0921efb665aff26b378f495e5ff84f7e3fe649d","https://github.com/python/cpython/commit/f2cd7ef89aa8a0dcbc7283bbd39548b76f2a736a","https://github.com/python/cpython/issues/143921","https://github.com/python/cpython/pull/143922","https://mail.python.org/archives/list/security-announce@python.org/thread/DD7C7JZJYTBXMDOWKCEIEBJLBRU64OMR/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15366","description":"The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters."}]},{"artifact":{"id":"8bc1c8460275f7b9","cpes":["cpe:2.3:a:python3-pkg-resources:python3-pkg-resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-pkg-resources:python3_pkg_resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_pkg_resources:python3-pkg-resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_pkg_resources:python3_pkg_resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-pkg:python3-pkg-resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3-pkg:python3_pkg_resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_pkg:python3-pkg-resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3_pkg:python3_pkg_resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3-pkg-resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*","cpe:2.3:a:python3:python3_pkg_resources:68.1.2-2ubuntu1.2:*:*:*:*:*:*:*"],"name":"python3-pkg-resources","purl":"pkg:deb/ubuntu/python3-pkg-resources@68.1.2-2ubuntu1.2?arch=all&distro=ubuntu-24.04&upstream=setuptools","type":"deb","version":"68.1.2-2ubuntu1.2","language":"","licenses":["Apache-2.0","BSD-3-Clause","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3-pkg-resources/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3-pkg-resources/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pkg-resources.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3-pkg-resources.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3-pkg-resources.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3-pkg-resources.list"},{"path":"/var/lib/dpkg/info/python3-pkg-resources.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3-pkg-resources.postinst"},{"path":"/var/lib/dpkg/info/python3-pkg-resources.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3-pkg-resources.prerm"}],"upstreams":[{"name":"setuptools"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-59890","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"setuptools","version":"68.1.2-2ubuntu1.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-59890","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"risk":0.20249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-59890"},"relatedVulnerabilities":[{"id":"CVE-2026-59890","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-59890","cwe":"CWE-176","type":"Primary","source":"security-advisories@github.com"},{"cve":"CVE-2026-59890","cwe":"CWE-697","type":"Primary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-59890","date":"2026-10-08","epss":0.00405,"percentile":0.32692}],"urls":["https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f","https://github.com/pypa/setuptools/releases/tag/v83.0.0","https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-59890","description":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-93990","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-93990","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"risk":0.20149999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-93990"},"relatedVulnerabilities":[{"id":"CVE-2026-93990","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.7},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-93990","cwe":"CWE-176","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-93990","date":"2026-10-08","epss":0.00403,"percentile":0.32479}],"urls":["https://blog.hartwork.org/posts/expat-2-8-5-released/","https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/commit/ff6e1d7e750bbe245178f51a47a965dc8342861a","https://github.com/libexpat/libexpat/pull/1282","https://github.com/libexpat/libexpat/releases/tag/R_2_8_5","https://www.vulncheck.com/advisories/expat-through-2.8.4-malformed-utf-16-acceptance-via-unchecked-surrogate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-93990","description":"Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-19553","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-19553","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"risk":0.20049999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-19553"},"relatedVulnerabilities":[{"id":"CVE-2026-19553","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-19553","cwe":"CWE-297","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-19553","date":"2026-10-08","epss":0.00401,"percentile":0.32247}],"urls":["https://github.com/python/cpython/commit/1697ea386c707142555d98a1263176bbbc014a96","https://github.com/python/cpython/commit/5867d4e4ae6d1062352baf6b497a4026e8578ccf","https://github.com/python/cpython/commit/641390146a16a38e6701923f4ee4f1940ae77082","https://github.com/python/cpython/commit/869069d52ce0efab2f8c38197e92cdaaa312f1ed","https://github.com/python/cpython/commit/966bf426d0b6c31c1b0a255ff14a17143a466ced","https://github.com/python/cpython/commit/bdebbf9b366ec91e9cd9daa0b3510c9e84b60b80","https://github.com/python/cpython/commit/f4e43ba525187282f2011da0e6ffc0d2b08d8062","https://github.com/python/cpython/issues/156793","https://github.com/python/cpython/pull/158503","https://mail.python.org/archives/list/security-announce@python.org/thread/QNZRG3YOAMTHDCMVCICXGY6YEFPY2VDL/","http://www.openwall.com/lists/oss-security/2026/09/30/16"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-19553","description":"ssl.SSLContext.wrap_bio() didn't require the server_hostname argument\nto not be None if ssl.SSLContext.check_hostname was set. Due to a\nmissing parameter check in SSLObject, if the server_hostname argument\nisn't supplied then hostname verification would be silently skipped.\n\n\nThis defect could lead to programs where certificate hostname verification\n*appeared* to be succeeding with SSLContext.check_hostname = True and no\nValueError being raised due to misconfiguration.\n\n\nIf the program passes a server_hostname value that isn't an empty string\nor None to any of these APIs then certificate hostname verification\nproceeds as expected and the program is not affected by this vulnerability.\n\n\nMitigating this vulnerability doesn't require updating Python or applying\nthe patch. To mitigate, pass a valid non-None and non-empty\nserver_hostname value to SSLContext.wrap_bio(),\nasyncio.create_connection(), or asyncio.loop.start_tls() and\ncertificate hostname verification will proceed as expected. Upgrading to\nthe latest version of Python or applying the patch only changes the\nbehavior from silently skipping hostname verification to raising a\nValueError, similar to SSLContext.wrap_socket(), when server_hostname\nisn't supplied."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86145","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86145","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"risk":0.197,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86145"},"relatedVulnerabilities":[{"id":"CVE-2026-86145","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":8.2,"impactScore":4.3,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86145","cwe":"CWE-424","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86145","date":"2026-10-08","epss":0.00394,"percentile":0.31423}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","http://www.openwall.com/lists/oss-security/2026/09/05/3"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86145","description":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5856","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5856","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"risk":0.19673,"urls":["https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/775960","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."},"relatedVulnerabilities":[{"id":"CVE-2026-42505","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-42505","cwe":"CWE-201","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-42505","date":"2026-10-08","epss":0.00382,"percentile":0.3011}],"urls":["https://go.dev/cl/775960","https://go.dev/issue/79282","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-5856"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-42505","description":"Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4603","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4603","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"risk":0.19202999999999998,"urls":["https://go.dev/issue/77954","https://go.dev/cl/752081"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\".\n\nA new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."},"relatedVulnerabilities":[{"id":"CVE-2026-27142","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27142","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27142","date":"2026-10-08","epss":0.00346,"percentile":0.26021}],"urls":["https://go.dev/cl/752081","https://go.dev/issue/77954","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4603"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27142","description":"Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value \"refresh\". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions in the meta content attribute which follow \"url=\" by setting htmlmetacontenturlescape=0."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4865","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4865","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763762","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied.\n\nThese issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."},"relatedVulnerabilities":[{"id":"CVE-2026-32289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32289","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32289","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/763762","https://go.dev/issue/78331","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4865"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32289","description":"Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. Additionally template actions within JS template literals did not properly track the brace depth, leading to incorrect escaping being applied. These issues could cause actions within JS template literals to be incorrectly or improperly escaped, leading to XSS vulnerabilities."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.10"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4982","versionConstraint":"<1.25.10||>=1.26.0-0,<1.26.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4982","fix":{"state":"fixed","versions":["1.25.10","1.26.3"],"available":[{"date":"2026-05-07","kind":"release","version":"1.25.10"},{"date":"2026-05-07","kind":"release","version":"1.26.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"risk":0.18481499999999998,"urls":["https://go.dev/cl/769920","https://groups.google.com/g/golang-announce/c/qcCIEXso47M"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78913","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-39823","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39823","cwe":"CWE-79","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39823","date":"2026-10-08","epss":0.00333,"percentile":0.24439}],"urls":["https://go.dev/cl/769920","https://go.dev/issue/78913","https://groups.google.com/g/golang-announce/c/qcCIEXso47M","https://pkg.go.dev/vuln/GO-2026-4982"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39823","description":"CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune inside of the <content> attribute, the escaper would fail to similarly escape it, leading to XSS."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-6879","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-6879","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-6879"},"relatedVulnerabilities":[{"id":"CVE-2026-6879","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-6879","cwe":"CWE-407","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-6879","date":"2026-10-08","epss":0.00369,"percentile":0.28673}],"urls":["https://github.com/python/cpython/commit/02c08e6b747ac43d0d866a4ffa916bedf3423f81","https://github.com/python/cpython/commit/037965c00a427cba5c05447efadc67c51a492e85","https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70","https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0","https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db","https://github.com/python/cpython/commit/96510a3758f4a075f43223afdee3b6ee1a7a7f02","https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3","https://github.com/python/cpython/issues/152674","https://github.com/python/cpython/pull/152676","https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-6879","description":"`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-15367","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.1845,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-15367"},"relatedVulnerabilities":[{"id":"CVE-2025-15367","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."}]},{"artifact":{"id":"14cfe0f375d6d1af","cpes":["cpe:2.3:a:zlib1g:zlib1g:1\\:1.3.dfsg-3.1ubuntu2.2:*:*:*:*:*:*:*"],"name":"zlib1g","purl":"pkg:deb/ubuntu/zlib1g@1%3A1.3.dfsg-3.1ubuntu2.2?arch=amd64&distro=ubuntu-24.04&upstream=zlib","type":"deb","version":"1:1.3.dfsg-3.1ubuntu2.2","language":"","licenses":["Zlib"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/zlib1g/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/zlib1g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/zlib1g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"zlib"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-85091","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"zlib","version":"1:1.3.dfsg-3.1ubuntu2.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-85091","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"risk":0.178,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-85091"},"relatedVulnerabilities":[{"id":"CVE-2026-85091","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.3},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-85091","cwe":"CWE-787","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-85091","date":"2026-10-08","epss":0.00356,"percentile":0.27225}],"urls":["https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490","https://github.com/madler/zlib","https://github.com/madler/zlib/blob/v1.3.2/gzwrite.c#L393","https://www.vulncheck.com/advisories/zlib-1.3.1.2-through-1.3.2-heap-buffer-overflow-via-gz-vacate"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-85091","description":"zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4970","versionConstraint":"<1.25.12||>=1.26.0-0,<1.26.5||>=1.27.0-0,<1.27.0-rc.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4970","fix":{"state":"fixed","versions":["1.25.12","1.26.5","1.27.0-rc.2"],"available":[{"date":"2026-07-07","kind":"release","version":"1.25.12"},{"date":"2026-07-07","kind":"release","version":"1.26.5"},{"date":"2026-07-07","kind":"release","version":"1.27.0-rc.2"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"risk":0.17748,"urls":["https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://go.dev/cl/797880"],"severity":"High","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/79005","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.\n\nFor example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."},"relatedVulnerabilities":[{"id":"CVE-2026-39822","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39822","cwe":"CWE-61","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39822","date":"2026-10-08","epss":0.00232,"percentile":0.12958}],"urls":["https://go.dev/cl/797880","https://go.dev/issue/79005","https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc","https://pkg.go.dev/vuln/GO-2026-4970"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39822","description":"On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open(\"symlink/\")' will open \"symlink\" even when \"symlink\" is a symbolic link pointing outside of the root."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-102633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102633","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"risk":0.174,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102633"},"relatedVulnerabilities":[{"id":"CVE-2026-102633","cvss":[{"type":"Primary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.2},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102633","cwe":"CWE-190","type":"Primary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-102633","date":"2026-10-08","epss":0.00348,"percentile":0.26342}],"urls":["https://github.com/libexpat/libexpat","https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/lib/xmlparse.c#L1003","https://github.com/libexpat/libexpat/commit/209801d7fbaf07ab74bae8cb32dd2ab9e5846118","https://github.com/libexpat/libexpat/pull/1392","https://www.vulncheck.com/advisories/libexpat-2.7.2-through-2.8.5-integer-overflow-in-expat-realloc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102633","description":"libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.13"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6091","versionConstraint":"<1.25.13||>=1.26.0-0,<1.26.6||>=1.27.0-0,<1.27.0-rc.3 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6091","fix":{"state":"fixed","versions":["1.25.13","1.26.6","1.27.0-rc.3"],"available":[{"date":"2026-08-13","kind":"release","version":"1.25.13"},{"date":"2026-08-13","kind":"release","version":"1.26.6"},{"date":"2026-08-13","kind":"release","version":"1.27.0-rc.3"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"risk":0.17204999999999998,"urls":["https://go.dev/cl/807100","https://groups.google.com/g/golang-announce/c/94pEornpRlI"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/80435","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."},"relatedVulnerabilities":[{"id":"CVE-2026-56858","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":6.1,"impactScore":2.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56858","cwe":"CWE-79","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-56858","date":"2026-10-08","epss":0.0031,"percentile":0.21812}],"urls":["https://go.dev/cl/807100","https://go.dev/issue/80435","https://groups.google.com/g/golang-announce/c/94pEornpRlI","https://pkg.go.dev/vuln/GO-2026-6091"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56858","description":"Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-8674","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-8674","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"risk":0.17099999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-8674"},"relatedVulnerabilities":[{"id":"CVE-2026-8674","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.3,"impactScore":3.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-8674","cwe":"CWE-617","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-8674","date":"2026-10-08","epss":0.00342,"percentile":0.2561}],"urls":["https://joshua.hu/fuzzing-glibc-libresolv","https://sourceware.org/bugzilla/show_bug.cgi?id=31026","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0021","https://sourceware.org/git/?p=glibc.git;a=commit;h=506ea57086bfb9ce3daff1c14246a1cb532aba0a","http://www.openwall.com/lists/oss-security/2026/09/17/4"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-8674","description":"Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.\n\nThe resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration.  The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion.  Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes.  Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.12"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4340","versionConstraint":"<1.24.12||>=1.25.0,<1.25.6 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4340","fix":{"state":"fixed","versions":["1.24.12","1.25.6"],"available":[{"date":"2026-01-15","kind":"release","version":"1.24.12"},{"date":"2026-01-15","kind":"release","version":"1.25.6"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"risk":0.169435,"urls":["https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/724120","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."},"relatedVulnerabilities":[{"id":"CVE-2025-61730","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":5.3,"impactScore":1.5,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"epss":[{"cve":"CVE-2025-61730","date":"2026-10-08","epss":0.00329,"percentile":0.23929}],"urls":["https://go.dev/cl/724120","https://go.dev/issue/76443","https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc","https://pkg.go.dev/vuln/GO-2026-4340"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61730","description":"During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosure if a network-local attacker can inject messages during the handshake."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4864","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4864","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"risk":0.16644,"urls":["https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763761","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root.\n\nThe Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."},"relatedVulnerabilities":[{"id":"CVE-2026-32282","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":6.4,"impactScore":5.9,"exploitabilityScore":0.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32282","cwe":"CWE-59","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32282","date":"2026-10-08","epss":0.00292,"percentile":0.19913}],"urls":["https://go.dev/cl/763761","https://go.dev/issue/78293","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4864"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32282","description":"On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.24.11"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2025-4175","versionConstraint":"<1.24.11||>=1.25.0,<1.25.5 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2025-4175","fix":{"state":"fixed","versions":["1.24.11","1.25.5"],"available":[{"date":"2025-12-02","kind":"release","version":"1.24.11"},{"date":"2025-12-02","kind":"release","version":"1.25.5"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"risk":0.1633,"urls":["https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/723900","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."},"relatedVulnerabilities":[{"id":"CVE-2025-61727","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-61727","cwe":"CWE-295","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2025-61727","date":"2026-10-08","epss":0.00284,"percentile":0.1914}],"urls":["https://go.dev/cl/723900","https://go.dev/issue/76442","https://groups.google.com/g/golang-announce/c/8FJoBkPddm4","https://pkg.go.dev/vuln/GO-2025-4175"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-61727","description":"An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com does not prevent a leaf certificate from claiming the SAN *.example.com."}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.52.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GHSA-qpw4-5x99-6vjp","versionConstraint":"<0.52.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"github:language:go"}}],"vulnerability":{"id":"GHSA-qpw4-5x99-6vjp","fix":{"state":"fixed","versions":["0.52.0"],"available":[{"date":"2026-07-07","kind":"first-observed","version":"0.52.0"}]},"cvss":[{"type":"Secondary","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39827","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39827","date":"2026-10-08","epss":0.00281,"percentile":0.18814}],"risk":0.16157499999999997,"urls":["https://nvd.nist.gov/vuln/detail/CVE-2026-39827","https://go.dev/cl/781320","https://go.dev/issue/35127","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5016"],"severity":"Medium","namespace":"github:language:go","advisories":[],"dataSource":"https://github.com/advisories/GHSA-qpw4-5x99-6vjp","description":"golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS"},"relatedVulnerabilities":[{"id":"CVE-2026-39827","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.5,"impactScore":3.6,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39827","cwe":"CWE-924","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-39827","date":"2026-10-08","epss":0.00281,"percentile":0.18814}],"urls":["https://go.dev/cl/781320","https://go.dev/issue/35127","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5016"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39827","description":"An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89156","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89156","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"risk":0.147,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89156"},"relatedVulnerabilities":[{"id":"CVE-2026-89156","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.9,"impactScore":3.6,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89156","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89156","date":"2026-10-08","epss":0.00294,"percentile":0.20148}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89156","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-97399","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-97399","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"risk":0.146,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-97399"},"relatedVulnerabilities":[{"id":"CVE-2026-97399","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-97399","cwe":"CWE-126","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-97399","date":"2026-10-08","epss":0.00292,"percentile":0.19916}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34683","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024","http://www.openwall.com/lists/oss-security/2026/09/28/7"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97399","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89157","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89157","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"risk":0.13899999999999998,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89157"},"relatedVulnerabilities":[{"id":"CVE-2026-89157","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.7,"impactScore":4.3,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89157","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89157","date":"2026-10-08","epss":0.00278,"percentile":0.18565}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89157","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89160","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89160","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"risk":0.134,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89160"},"relatedVulnerabilities":[{"id":"CVE-2026-89160","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","metrics":{"baseScore":6.5,"impactScore":2.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.7,"impactScore":1.5,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89160","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89160","date":"2026-10-08","epss":0.00268,"percentile":0.17337}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89160","description":"PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89092","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89092","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89092"},"relatedVulnerabilities":[{"id":"CVE-2026-89092","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89092","cwe":"CWE-789","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-89092","date":"2026-10-08","epss":0.00265,"percentile":0.16924}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34624","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016","http://www.openwall.com/lists/oss-security/2026/09/11/2"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092","description":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service."}]},{"artifact":{"id":"d89ef5f93ba22208","cpes":["cpe:2.3:a:libpam-modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules","purl":"pkg:deb/ubuntu/libpam-modules@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam-modules/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"dbc0224a08459408","cpes":["cpe:2.3:a:libpam-modules-bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules-bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules_bin:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_modules:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-modules-bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_modules_bin:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-modules-bin","purl":"pkg:deb/ubuntu/libpam-modules-bin@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-modules-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam-modules-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-modules-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.list"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postinst"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.postrm"},{"path":"/var/lib/dpkg/info/libpam-modules-bin.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-modules-bin.prerm"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"8213e07a58a8ec78","cpes":["cpe:2.3:a:libpam-runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam-runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam_runtime:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam-runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*","cpe:2.3:a:libpam:libpam_runtime:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam-runtime","purl":"pkg:deb/ubuntu/libpam-runtime@1.5.3-5ubuntu5.7?arch=all&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam-runtime/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam-runtime/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam-runtime.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.list"},{"path":"/var/lib/dpkg/info/libpam-runtime.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.postinst"},{"path":"/var/lib/dpkg/info/libpam-runtime.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.postrm"},{"path":"/var/lib/dpkg/info/libpam-runtime.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.prerm"},{"path":"/var/lib/dpkg/info/libpam-runtime.templates","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam-runtime.templates"}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"16e6be2ba255a19b","cpes":["cpe:2.3:a:libpam0g:libpam0g:1.5.3-5ubuntu5.7:*:*:*:*:*:*:*"],"name":"libpam0g","purl":"pkg:deb/ubuntu/libpam0g@1.5.3-5ubuntu5.7?arch=amd64&distro=ubuntu-24.04&upstream=pam","type":"deb","version":"1.5.3-5ubuntu5.7","language":"","licenses":["BSD-3-clause","BSD-tcp_wrappers","Beerware","GPL","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2","LGPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpam0g/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpam0g/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpam0g:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pam"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-10041","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pam","version":"1.5.3-5ubuntu5.7"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-10041","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"risk":0.1325,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-10041"},"relatedVulnerabilities":[{"id":"CVE-2024-10041","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","metrics":{"baseScore":4.7,"impactScore":3.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"secalert@redhat.com"},{"cve":"CVE-2024-10041","cwe":"CWE-922","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2024-10041","date":"2026-10-08","epss":0.00265,"percentile":0.16907}],"urls":["https://access.redhat.com/errata/RHSA-2024:10379","https://access.redhat.com/errata/RHSA-2024:11250","https://access.redhat.com/errata/RHSA-2024:9941","https://access.redhat.com/security/cve/CVE-2024-10041","https://bugzilla.redhat.com/show_bug.cgi?id=2319212","https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/commit/b7b96362087414e52524d3d9d9b3faa21e1db620","https://github.com/linux-pam/linux-pam/pull/b3020da7da384d769f27a8713257fbe1001878be","https://github.com/linux-pam/linux-pam/pull/b7b96362087414e52524d3d9d9b3faa21e1db620"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-10041","description":"A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications."}]},{"artifact":{"id":"cd80a8862611238d","cpes":["cpe:2.3:a:coreutils:coreutils:9.4-3ubuntu6.3:*:*:*:*:*:*:*"],"name":"coreutils","purl":"pkg:deb/ubuntu/coreutils@9.4-3ubuntu6.3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"9.4-3ubuntu6.3","language":"","licenses":["BSD-4-clause-UC","FSFULLR","GFDL-1.3","GFDL-NIV-1.3","GPL-3","GPL-3+","ISC"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/coreutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/coreutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/coreutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/coreutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/coreutils.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2016-2781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"coreutils","version":"9.4-3ubuntu6.3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-2781","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"risk":0.1284,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-2781"},"relatedVulnerabilities":[{"id":"CVE-2016-2781","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","metrics":{"baseScore":6.5,"impactScore":4,"exploitabilityScore":2.1},"version":"3.0","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","metrics":{"baseScore":2.1,"impactScore":2.9,"exploitabilityScore":4},"version":"2.0","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","metrics":{"baseScore":4.6,"impactScore":2.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2016-2781","cwe":"CWE-20","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2016-2781","date":"2026-10-08","epss":0.00428,"percentile":0.35056}],"urls":["http://www.openwall.com/lists/oss-security/2016/02/28/2","http://www.openwall.com/lists/oss-security/2016/02/28/3","https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-2781","description":"chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer."}]},{"artifact":{"id":"271cbc4b0386e5d1","cpes":["cpe:2.3:a:login:login:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"login","purl":"pkg:deb/ubuntu/login@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/login/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/login/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/login.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.list"},{"path":"/var/lib/dpkg/info/login.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.postinst"},{"path":"/var/lib/dpkg/info/login.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.postrm"},{"path":"/var/lib/dpkg/info/login.preinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.preinst"},{"path":"/var/lib/dpkg/info/login.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/login.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"12ce9c7a4baa2c69","cpes":["cpe:2.3:a:passwd:passwd:1\\:4.13\\+dfsg1-4ubuntu3.2:*:*:*:*:*:*:*"],"name":"passwd","purl":"pkg:deb/ubuntu/passwd@1%3A4.13%2Bdfsg1-4ubuntu3.2?arch=amd64&distro=ubuntu-24.04&upstream=shadow","type":"deb","version":"1:4.13+dfsg1-4ubuntu3.2","language":"","licenses":["BSD-3-clause","GPL-1","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/passwd/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/passwd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/passwd.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.list"},{"path":"/var/lib/dpkg/info/passwd.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.postinst"},{"path":"/var/lib/dpkg/info/passwd.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.postrm"},{"path":"/var/lib/dpkg/info/passwd.preinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.preinst"},{"path":"/var/lib/dpkg/info/passwd.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/passwd.prerm"}],"upstreams":[{"name":"shadow"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2024-56433","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"shadow","version":"1:4.13+dfsg1-4ubuntu3.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2024-56433","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"risk":0.1278,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2024-56433"},"relatedVulnerabilities":[{"id":"CVE-2024-56433","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2024-56433","cwe":"CWE-1188","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2024-56433","date":"2026-10-08","epss":0.00426,"percentile":0.34901}],"urls":["https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241","https://github.com/shadow-maint/shadow/issues/1157","https://github.com/shadow-maint/shadow/releases/tag/4.4"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2024-56433","description":"shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid."}]},{"artifact":{"id":"9399a526f720c3e2","cpes":["cpe:2.3:a:libicu74:libicu74:74.2-1ubuntu3.1:*:*:*:*:*:*:*"],"name":"libicu74","purl":"pkg:deb/ubuntu/libicu74@74.2-1ubuntu3.1?arch=amd64&distro=ubuntu-24.04&upstream=icu","type":"deb","version":"74.2-1ubuntu3.1","language":"","licenses":["GPL-3","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libicu74/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libicu74/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libicu74:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libicu74:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"icu"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-5222","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"icu","version":"74.2-1ubuntu3.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-5222","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-5222","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5222","date":"2026-10-08","epss":0.00425,"percentile":0.34769}],"risk":0.1275,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-5222"},"relatedVulnerabilities":[{"id":"CVE-2025-5222","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-5222","cwe":"CWE-120","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2025-5222","date":"2026-10-08","epss":0.00425,"percentile":0.34769}],"urls":["https://access.redhat.com/errata/RHSA-2025:11888","https://access.redhat.com/errata/RHSA-2025:12083","https://access.redhat.com/errata/RHSA-2025:12331","https://access.redhat.com/errata/RHSA-2025:12332","https://access.redhat.com/errata/RHSA-2025:12333","https://access.redhat.com/errata/RHSA-2026:54544","https://access.redhat.com/errata/RHSA-2026:54553","https://access.redhat.com/errata/RHSA-2026:54581","https://access.redhat.com/errata/RHSA-2026:56786","https://access.redhat.com/errata/RHSA-2026:56853","https://access.redhat.com/errata/RHSA-2026:56911","https://access.redhat.com/errata/RHSA-2026:60019","https://access.redhat.com/errata/RHSA-2026:65839","https://access.redhat.com/security/cve/CVE-2025-5222","https://bugzilla.redhat.com/show_bug.cgi?id=2368600","https://unicode-org.atlassian.net/jira/software/c/projects/ICU/issues/ICU-22957","https://lists.debian.org/debian-lts-announce/2025/06/msg00015.html","https://cert-portal.siemens.com/productcert/html/ssa-585531.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-5222","description":"A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-84366","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-84366","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"risk":0.127,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-84366"},"relatedVulnerabilities":[{"id":"CVE-2026-84366","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-84366","cwe":"CWE-319","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-84366","date":"2026-10-08","epss":0.00254,"percentile":0.15619}],"urls":["https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b","https://github.com/scrapy/scrapy/releases/tag/2.17.0","https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-84366","description":"Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta[\"is_secure\"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A network attacker who can observe traffic between Scrapy and S3 can read the bucket and key path, AWS Authorization header, X-Amz-Security-Token when temporary credentials are used, S3 object contents, and S3 response headers. An active man-in-the-middle attacker can also modify the plaintext S3 response body, status code, and headers before Scrapy processes them, causing scraped-data poisoning, poisoned exports, HTTP cache poisoning when caching is enabled, or influence over later crawl targets through forged redirects or attacker-controlled links. Users making S3-scheme requests with AWS credentials are affected. This issue is fixed in version 2.17.0."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89158","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89158","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"risk":0.1235,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89158"},"relatedVulnerabilities":[{"id":"CVE-2026-89158","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":6.5,"impactScore":4.3,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89158","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89158","date":"2026-10-08","epss":0.00247,"percentile":0.14628}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89158","description":"PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57175","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57175","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"risk":0.11399999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57175"},"relatedVulnerabilities":[{"id":"CVE-2026-57175","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.4,"impactScore":5.2,"exploitabilityScore":1.2},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57175","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57175","date":"2026-10-08","epss":0.00228,"percentile":0.12443}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vq6g-g6c7-5f2j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57175","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-3446","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-3446","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"risk":0.11249999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-3446"},"relatedVulnerabilities":[{"id":"CVE-2026-3446","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-3446","cwe":"CWE-345","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-3446","date":"2026-10-08","epss":0.00225,"percentile":0.12174}],"urls":["https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474","https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e","https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa","https://github.com/python/cpython/issues/145264","https://github.com/python/cpython/pull/145267","https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-3446","description":"When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use \"validate=True\" to enable stricter processing of base64 data."}]},{"artifact":{"id":"1fe29ec161099bff","cpes":["cpe:2.3:a:wget:wget:1.21.4-1ubuntu4.5:*:*:*:*:*:*:*"],"name":"wget","purl":"pkg:deb/ubuntu/wget@1.21.4-1ubuntu4.5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.21.4-1ubuntu4.5","language":"","licenses":["sha256:c58cb5a2d94f35f0e9b0f1a038d48b73477aa12782ff17328c21d8a86f5f99d5"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/wget/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/wget/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/wget.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/wget.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-16599","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"wget","version":"1.21.4-1ubuntu4.5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-16599","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"risk":0.11249999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-16599"},"relatedVulnerabilities":[{"id":"CVE-2026-16599","cvss":[{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-16599","cwe":"CWE-606","type":"Primary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-16599","date":"2026-10-08","epss":0.00375,"percentile":0.29337}],"urls":["https://cert.pl/en/posts/2026/08/CVE-2026-16599","https://gitlab.com/gnuwget/wget","https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-16599","description":"GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.\n\n\nThis issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa"}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2016-20013","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2016-20013","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"risk":0.1117,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2016-20013"},"relatedVulnerabilities":[{"id":"CVE-2016-20013","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":7.5,"impactScore":3.6,"exploitabilityScore":3.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","metrics":{"baseScore":5,"impactScore":2.9,"exploitabilityScore":10},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2016-20013","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2016-20013","date":"2026-10-08","epss":0.02234,"percentile":0.82254}],"urls":["https://akkadia.org/drepper/SHA-crypt.txt","https://pthree.org/2018/05/23/do-not-use-sha256crypt-sha512crypt-theyre-dangerous/","https://twitter.com/solardiz/status/795601240151457793"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2016-20013","description":"sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57176","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57176","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"risk":0.1095,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57176"},"relatedVulnerabilities":[{"id":"CVE-2026-57176","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.8,"impactScore":5.2,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57176","cwe":"CWE-289","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57176","date":"2026-10-08","epss":0.00219,"percentile":0.11312}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-fp7w-m676-w7gc"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57176","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76642","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76642","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"risk":0.108,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76642"},"relatedVulnerabilities":[{"id":"CVE-2026-76642","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.5},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76642","cwe":"CWE-390","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-76642","date":"2026-10-08","epss":0.00216,"percentile":0.10995}],"urls":["https://github.com/util-linux/util-linux","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L476","https://github.com/util-linux/util-linux/blob/v2.42.2/libmount/src/context_mount.c#L892","https://github.com/util-linux/util-linux/commit/1d14676ea70003e9f5b2a6a76af0cadb1190411a","https://github.com/util-linux/util-linux/commit/a15c00a9e545aa8b9cf6ec0f888ff6c7b3eaeedc","https://github.com/util-linux/util-linux/commit/f57cea130839c0af8dc0525274267ae4cfd66bbf","https://github.com/util-linux/util-linux/security/advisories/GHSA-m25x-3hj9-m26f","https://www.vulncheck.com/advisories/util-linux-libmount-privilege-escalation-via-failed-mount-helper"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76642","description":"util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-103111","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-103111","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"risk":0.107,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-103111"},"relatedVulnerabilities":[{"id":"CVE-2026-103111","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","metrics":{"baseScore":7.6,"impactScore":4.8,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-103111","cwe":"CWE-787","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-103111","date":"2026-10-08","epss":0.00214,"percentile":0.10812}],"urls":["https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-r9hj-j2rw-4q3m","https://lists.debian.org/debian-lts-announce/2026/10/msg00008.html"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-103111","description":"PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-82049","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-82049","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"risk":0.1045,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-82049"},"relatedVulnerabilities":[{"id":"CVE-2026-82049","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-82049","cwe":"CWE-59","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-82049","date":"2026-10-08","epss":0.00209,"percentile":0.10206}],"urls":["https://github.com/python/cpython/commit/197663d63afed27f66e10e23c194e8a634e60913","https://github.com/python/cpython/commit/28f315486b3da0352b9a1de1c3c97f4127ba4771","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://github.com/python/cpython/commit/c66df4e70435d257fd488b35ea129c6f317433a8","https://github.com/python/cpython/commit/cc1689830c6b9aaddded2fb9f2fe8116867e2c0e","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049","description":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree."}]},{"artifact":{"id":"ee06eab4d33d40b1","cpes":["cpe:2.3:a:libexpat1:libexpat1:2.6.1-2ubuntu0.6:*:*:*:*:*:*:*"],"name":"libexpat1","purl":"pkg:deb/ubuntu/libexpat1@2.6.1-2ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=expat","type":"deb","version":"2.6.1-2ubuntu0.6","language":"","licenses":["MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libexpat1/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libexpat1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libexpat1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"expat"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-66382","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"expat","version":"2.6.1-2ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-66382","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"risk":0.1015,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-66382"},"relatedVulnerabilities":[{"id":"CVE-2025-66382","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-66382","cwe":"CWE-407","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2025-66382","date":"2026-10-08","epss":0.00203,"percentile":0.09372}],"urls":["https://github.com/libexpat/libexpat/issues/1076","http://www.openwall.com/lists/oss-security/2025/12/02/1","https://cert-portal.siemens.com/productcert/html/ssa-082556.html","https://cert-portal.siemens.com/productcert/html/ssa-253495.html"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-66382","description":"In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86137","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86137","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"risk":0.09749999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86137"},"relatedVulnerabilities":[{"id":"CVE-2026-86137","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L","metrics":{"baseScore":6.1,"impactScore":4.3,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86137","cwe":"CWE-125","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86137","date":"2026-10-08","epss":0.00195,"percentile":0.08398}],"urls":["https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86137","description":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86143","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86143","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"risk":0.097,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86143"},"relatedVulnerabilities":[{"id":"CVE-2026-86143","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":7.3,"impactScore":5.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86143","cwe":"CWE-192","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86143","date":"2026-10-08","epss":0.00194,"percentile":0.08256}],"urls":["https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86143","description":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4869","versionConstraint":"<1.25.9||>=1.26.0-0,<1.26.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4869","fix":{"state":"fixed","versions":["1.25.9","1.26.2"],"available":[{"date":"2026-04-07","kind":"release","version":"1.25.9"},{"date":"2026-04-07","kind":"release","version":"1.26.2"}]},"cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"risk":0.09555000000000001,"urls":["https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"],"severity":"Medium","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/763766","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."},"relatedVulnerabilities":[{"id":"CVE-2026-32288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-32288","cwe":"CWE-770","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-32288","date":"2026-10-08","epss":0.00182,"percentile":0.07143}],"urls":["https://go.dev/cl/763766","https://go.dev/issue/78301","https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU","https://pkg.go.dev/vuln/GO-2026-4869"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-32288","description":"tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the \"old GNU sparse map\" format."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86144","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86144","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86144"},"relatedVulnerabilities":[{"id":"CVE-2026-86144","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","metrics":{"baseScore":5.6,"impactScore":3.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86144","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86144","date":"2026-10-08","epss":0.00186,"percentile":0.07567}],"urls":["https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86144","description":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78408","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78408","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"risk":0.093,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78408"},"relatedVulnerabilities":[{"id":"CVE-2026-78408","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H","metrics":{"baseScore":7.9,"impactScore":5.8,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78408","cwe":"CWE-775","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78408","date":"2026-10-08","epss":0.00186,"percentile":0.07549}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78408","https://bugzilla.redhat.com/show_bug.cgi?id=2522497","https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj","http://www.openwall.com/lists/oss-security/2026/09/05/2"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78408","description":"The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-12345","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.09,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-12345"},"relatedVulnerabilities":[{"id":"CVE-2026-12345","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"b99f35328df2c1c9","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/ubuntu/gnupg-l10n@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"5995b623e873af09","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/ubuntu/gpg-wks-client@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2022-3219","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2022-3219","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"risk":0.08789999999999999,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2022-3219"},"relatedVulnerabilities":[{"id":"CVE-2022-3219","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Primary","source":"nvd@nist.gov"},{"cve":"CVE-2022-3219","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2022-3219","date":"2026-10-08","epss":0.00293,"percentile":0.20038}],"urls":["https://access.redhat.com/security/cve/CVE-2022-3219","https://bugzilla.redhat.com/show_bug.cgi?id=2127010","https://dev.gnupg.org/D556","https://dev.gnupg.org/T5993","https://marc.info/?l=oss-security&m=165696590211434&w=4","https://security.netapp.com/advisory/ntap-20230324-0001/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2022-3219","description":"GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-76781","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-76781","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"risk":0.0835,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-76781"},"relatedVulnerabilities":[{"id":"CVE-2026-76781","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-76781","cwe":"CWE-476","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-76781","date":"2026-10-08","epss":0.00167,"percentile":0.05427}],"urls":["https://access.redhat.com/errata/RHSA-2026:57604","https://access.redhat.com/security/cve/CVE-2026-76781","https://bugzilla.redhat.com/show_bug.cgi?id=2519776","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c6324894","https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/442"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-76781","description":"A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` attribute, leading to the application crashing and causing a Denial of Service (DoS)."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86139","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86139","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86139","date":"2026-10-08","epss":0.00166,"percentile":0.05341}],"risk":0.083,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86139"},"relatedVulnerabilities":[{"id":"CVE-2026-86139","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86139","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86139","date":"2026-10-08","epss":0.00166,"percentile":0.05341}],"urls":["https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86139","description":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86141","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86141","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86141","cwe":"CWE-252","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86141","date":"2026-10-08","epss":0.00165,"percentile":0.05259}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86141"},"relatedVulnerabilities":[{"id":"CVE-2026-86141","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86141","cwe":"CWE-252","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86141","date":"2026-10-08","epss":0.00165,"percentile":0.05259}],"urls":["https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86141","description":"xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-49839","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-49839","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"risk":0.0825,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-49839"},"relatedVulnerabilities":[{"id":"CVE-2026-49839","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-49839","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-49839","date":"2026-10-08","epss":0.00165,"percentile":0.05185}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-cfh2-vwfq-qfmm"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-49839","description":"jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds. When jv_load_file(raw=1) reads an attacker-controlled file, it repeatedly appends file chunks to the same jv string accumulator. Once jv_string_append_buf() returns jv_invalid_with_msg(\"String too long\"), the raw-file loop does not stop. If the file contains at least one more byte, the next loop iteration appends a new chunk to an object that is already invalid. With assertions enabled this aborts in jvp_string_ptr(). With assertions disabled, the invalid object is interpreted as a string object and ASan reports heap-buffer-overflow. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57178","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57178","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"risk":0.08,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57178"},"relatedVulnerabilities":[{"id":"CVE-2026-57178","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.4,"impactScore":5.2,"exploitabilityScore":2.3},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57178","cwe":"CWE-287","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-57178","cwe":"CWE-347","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57178","date":"2026-10-08","epss":0.0016,"percentile":0.04623}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-3c93-f73f-qc9h"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57178","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `api_id`, and `api_result`, potentially allowing authentication as an arbitrary VK user ID. The issue affects only applications using the `vk-app` backend. The issue has been fixed in version 5.0.0 by requiring `auth_key` to be present and valid before callback data is trusted."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57179","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57179","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"risk":0.079,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57179"},"relatedVulnerabilities":[{"id":"CVE-2026-57179","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.2,"impactScore":2.6,"exploitabilityScore":1.7},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57179","cwe":"CWE-384","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57179","date":"2026-10-08","epss":0.00158,"percentile":0.04336}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-vqg6-3fw6-j9jg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57179","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's browser to resume that attacker-controlled flow. This could authenticate the victim's browser as the attacker's account. The issue affects applications using partial pipeline steps such as `mail_validation` or custom steps decorated with `@partial`. The issue has been fixed in version 5.0.0 by binding partial pipeline resumes to the originating browser session."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41256","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41256","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41256"},"relatedVulnerabilities":[{"id":"CVE-2026-41256","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41256","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41256","date":"2026-10-08","epss":0.00157,"percentile":0.04291}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-vf2h-chrj-q3fg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41256","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by \\x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86142","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86142","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"risk":0.0785,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86142"},"relatedVulnerabilities":[{"id":"CVE-2026-86142","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86142","cwe":"CWE-122","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86142","date":"2026-10-08","epss":0.00157,"percentile":0.04231}],"urls":["https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86142","description":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40612","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40612","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40612"},"relatedVulnerabilities":[{"id":"CVE-2026-40612","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40612","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-40612","date":"2026-10-08","epss":0.00156,"percentile":0.04182}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-r7m6-x9c7-h69j"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40612","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with reduce, since the JSON parser caps at depth 10000), the C stack is exhausted."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-44777","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-44777","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-44777"},"relatedVulnerabilities":[{"id":"CVE-2026-44777","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-44777","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-44777","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-rmpv-jgvr-wpr9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-44777","description":"jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two\notherwise valid modules include each other."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-47770","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-47770","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-47770"},"relatedVulnerabilities":[{"id":"CVE-2026-47770","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-47770","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-47770","date":"2026-10-08","epss":0.00156,"percentile":0.04181}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-3pgx-frr7-3jxp"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-47770","description":"jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operator exhausts the C stack on jq's ordinary command-line surface, resulting in denial of service via stack exhaustion (uncontrolled recursion). The crash occurs in jq's recursive structural comparison code, with the recursion repeating through jvp_array_equal() and jv_equal() in src/jv.c when comparing deeply nested arrays; a nearby sort comparator path through jv_cmp() in src/jv_aux.c overflows the stack at a larger nesting depth from  the same missing recursion guard. Anyone running jq comparisons on attacker-controlled deeply nested JSON values, or embedding jq in a context  where untrusted data can reach the == comparison path, is affected. This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89162","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89162","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89162"},"relatedVulnerabilities":[{"id":"CVE-2026-89162","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89162","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89162","date":"2026-10-08","epss":0.00156,"percentile":0.04152}],"urls":["https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89162","description":"In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78410","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78410","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"risk":0.078,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78410"},"relatedVulnerabilities":[{"id":"CVE-2026-78410","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78410","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78410","date":"2026-10-08","epss":0.00156,"percentile":0.04148}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78410","https://bugzilla.redhat.com/show_bug.cgi?id=2522684","https://github.com/util-linux/util-linux/security/advisories/GHSA-rh77-686x-2f2m"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78410","description":"A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode."}]},{"artifact":{"id":"3f97bf43ff1778dc","cpes":["cpe:2.3:a:bsdutils:bsdutils:1\\:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"bsdutils","purl":"pkg:deb/ubuntu/bsdutils@1%3A2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux%402.39.3-9ubuntu6.6","type":"deb","version":"1:2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/bsdutils/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/bsdutils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/bsdutils.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/bsdutils.list"}],"upstreams":[{"name":"util-linux","version":"2.39.3-9ubuntu6.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"cb5c6761273d29c4","cpes":["cpe:2.3:a:libblkid1:libblkid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libblkid1","purl":"pkg:deb/ubuntu/libblkid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libblkid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libblkid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libblkid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"c02905cff08d2f0f","cpes":["cpe:2.3:a:libmount1:libmount1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libmount1","purl":"pkg:deb/ubuntu/libmount1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libmount1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libmount1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libmount1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libmount1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"e0380baf79d39c85","cpes":["cpe:2.3:a:libsmartcols1:libsmartcols1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libsmartcols1","purl":"pkg:deb/ubuntu/libsmartcols1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsmartcols1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsmartcols1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsmartcols1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"ee5b3d781052e1ec","cpes":["cpe:2.3:a:libuuid1:libuuid1:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"libuuid1","purl":"pkg:deb/ubuntu/libuuid1@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libuuid1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libuuid1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libuuid1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"1bddfbdf64661f04","cpes":["cpe:2.3:a:mount:mount:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"mount","purl":"pkg:deb/ubuntu/mount@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04&upstream=util-linux","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/mount/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/mount/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/mount.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/mount.list"}],"upstreams":[{"name":"util-linux"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"f1e4c52ae1a4fa42","cpes":["cpe:2.3:a:util-linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util-linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util_linux:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util-linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*","cpe:2.3:a:util:util_linux:2.39.3-9ubuntu6.6:*:*:*:*:*:*:*"],"name":"util-linux","purl":"pkg:deb/ubuntu/util-linux@2.39.3-9ubuntu6.6?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.39.3-9ubuntu6.6","language":"","licenses":["BSD-3-clause","BSD-4-clause","BSLA","GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MIT","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/util-linux/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/util-linux/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/util-linux.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.list"},{"path":"/var/lib/dpkg/info/util-linux.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postinst"},{"path":"/var/lib/dpkg/info/util-linux.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.postrm"},{"path":"/var/lib/dpkg/info/util-linux.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/util-linux.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-78409","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"util-linux","version":"2.39.3-9ubuntu6.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-78409","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"risk":0.077,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-78409"},"relatedVulnerabilities":[{"id":"CVE-2026-78409","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7,"impactScore":5.9,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-78409","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-78409","date":"2026-10-08","epss":0.00154,"percentile":0.03965}],"urls":["https://access.redhat.com/errata/RHSA-2026:63162","https://access.redhat.com/security/cve/CVE-2026-78409","https://bugzilla.redhat.com/show_bug.cgi?id=2522607","https://github.com/util-linux/util-linux/security/advisories/GHSA-8f2p-47x3-43mv"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78409","description":"The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43894","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43894","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43894"},"relatedVulnerabilities":[{"id":"CVE-2026-43894","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43894","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43894","date":"2026-10-08","epss":0.00153,"percentile":0.03894}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-5v7p-2r57-2g4g"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43894","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic. The wrapped negative value bypasses the heap-allocation size check, causes the function to use a 30-byte stack buffer, and then writes ≈715 million 16-bit units (≈1.4 GiB) at an offset 1.43 GiB below the stack frame. The written content is fully attacker-controlled (the parsed decimal digits, packed 3-per-unit)."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54369","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54369","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"risk":0.0765,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54369"},"relatedVulnerabilities":[{"id":"CVE-2026-54369","cvss":[{"type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":8.4},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":7.1,"impactScore":5.2,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"disclosure@vulncheck.com"},{"cve":"CVE-2026-54369","cwe":"CWE-59","type":"Secondary","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"epss":[{"cve":"CVE-2026-54369","date":"2026-10-08","epss":0.00153,"percentile":0.03888}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions","https://access.redhat.com/errata/RHSA-2026:34351","https://access.redhat.com/errata/RHSA-2026:42736","https://access.redhat.com/errata/RHSA-2026:42739","https://access.redhat.com/errata/RHSA-2026:43420","https://access.redhat.com/errata/RHSA-2026:44481","https://access.redhat.com/errata/RHSA-2026:46836","https://access.redhat.com/errata/RHSA-2026:50205","https://access.redhat.com/errata/RHSA-2026:53371","https://access.redhat.com/errata/RHSA-2026:54769","https://access.redhat.com/errata/RHSA-2026:58981","https://access.redhat.com/errata/RHSA-2026:64805","https://access.redhat.com/errata/RHSA-2026:67140","https://access.redhat.com/errata/RHSA-2026:67142","https://access.redhat.com/errata/RHSA-2026:67144","https://access.redhat.com/security/cve/CVE-2026-54369","https://bugzilla.redhat.com/show_bug.cgi?id=2490277","https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54369","description":"acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43895","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43895","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"risk":0.0755,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43895"},"relatedVulnerabilities":[{"id":"CVE-2026-43895","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43895","cwe":"CWE-20","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-43895","cwe":"CWE-158","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43895","date":"2026-10-08","epss":0.00151,"percentile":0.03747}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-7q7g-mrq3-phxr"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43895","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during module and data-file lookup. This creates a mismatch between the logical import string that policy or audit code may validate and the on-disk path that jq actually opens."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-43896","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-43896","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"risk":0.075,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-43896"},"relatedVulnerabilities":[{"id":"CVE-2026-43896","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":6.2,"impactScore":3.6,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-43896","cwe":"CWE-674","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-43896","date":"2026-10-08","epss":0.0015,"percentile":0.03619}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-mg96-6h3q-g846"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-43896","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachable through the * operator when both operands are objects."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54679","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54679","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"risk":0.0735,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54679"},"relatedVulnerabilities":[{"id":"CVE-2026-54679","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54679","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-54679","date":"2026-10-08","epss":0.00147,"percentile":0.03405}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-29gj-222p-j7vx"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54679","description":"jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple overflowing and then causing a massive buffer overrun.  This vulnerability is fixed in 1.8.2."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102474","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102474","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102474"},"relatedVulnerabilities":[{"id":"CVE-2026-102474","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":4,"impactScore":1.5,"exploitabilityScore":2.6},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102474","cwe":"CWE-787","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102474","date":"2026-10-08","epss":0.00144,"percentile":0.03187}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102474","https://bugzilla.redhat.com/show_bug.cgi?id=2543004"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102474","description":"A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \\u or \\U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18374","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18374","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"risk":0.07200000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18374"},"relatedVulnerabilities":[{"id":"CVE-2026-18374","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","metrics":{"baseScore":4.9,"impactScore":3.4,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"},{"cve":"CVE-2026-18374","cwe":"CWE-787","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-18374","date":"2026-10-08","epss":0.00144,"percentile":0.03179}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34574","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0015","http://www.openwall.com/lists/oss-security/2026/08/27/6"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374","description":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18508","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18508","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18508"},"relatedVulnerabilities":[{"id":"CVE-2026-18508","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","metrics":{"baseScore":4.4,"impactScore":2.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18508","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18508","date":"2026-10-08","epss":0.00141,"percentile":0.02947}],"urls":["https://access.redhat.com/errata/RHSA-2026:50807","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18508","https://bugzilla.redhat.com/show_bug.cgi?id=2509843"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18508","description":"A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction."}]},{"artifact":{"id":"e6722c56b9446394","cpes":["cpe:2.3:a:gir1.2-glib-2.0:gir1.2-glib-2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2-glib-2.0:gir1.2_glib_2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2_glib_2.0:gir1.2-glib-2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2_glib_2.0:gir1.2_glib_2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2-glib:gir1.2-glib-2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2-glib:gir1.2_glib_2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2_glib:gir1.2-glib-2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2_glib:gir1.2_glib_2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2:gir1.2-glib-2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:gir1.2:gir1.2_glib_2.0:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*"],"name":"gir1.2-glib-2.0","purl":"pkg:deb/ubuntu/gir1.2-glib-2.0@2.80.0-6ubuntu3.9?arch=amd64&distro=ubuntu-24.04&upstream=glib2.0","type":"deb","version":"2.80.0-6ubuntu3.9","language":"","licenses":["AFL-2.0","Apache-2.0","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MPL-1.1","Mingw-PD","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6","cmph","old-glib-tests"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gir1.2-glib-2.0/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/gir1.2-glib-2.0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gir1.2-glib-2.0:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/gir1.2-glib-2.0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glib2.0","version":"2.80.0-6ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86469","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86469"},"relatedVulnerabilities":[{"id":"CVE-2026-86469","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."}]},{"artifact":{"id":"b74f6733678f8812","cpes":["cpe:2.3:a:libglib2.0-0t64:libglib2.0-0t64:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-0t64:libglib2.0_0t64:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0-0t64:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_0t64:libglib2.0_0t64:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-0t64:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_0t64:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*"],"name":"libglib2.0-0t64","purl":"pkg:deb/ubuntu/libglib2.0-0t64@2.80.0-6ubuntu3.9?arch=amd64&distro=ubuntu-24.04&upstream=glib2.0","type":"deb","version":"2.80.0-6ubuntu3.9","language":"","licenses":["AFL-2.0","Apache-2.0","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MPL-1.1","Mingw-PD","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6","cmph","old-glib-tests"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-0t64/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libglib2.0-0t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libglib2.0-0t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glib2.0","version":"2.80.0-6ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86469","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86469"},"relatedVulnerabilities":[{"id":"CVE-2026-86469","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."}]},{"artifact":{"id":"b095b5fa7e893501","cpes":["cpe:2.3:a:libglib2.0-data:libglib2.0-data:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0-data:libglib2.0_data:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0-data:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0_data:libglib2.0_data:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0-data:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*","cpe:2.3:a:libglib2.0:libglib2.0_data:2.80.0-6ubuntu3.9:*:*:*:*:*:*:*"],"name":"libglib2.0-data","purl":"pkg:deb/ubuntu/libglib2.0-data@2.80.0-6ubuntu3.9?arch=all&distro=ubuntu-24.04&upstream=glib2.0","type":"deb","version":"2.80.0-6ubuntu3.9","language":"","licenses":["AFL-2.0","Apache-2.0","CC-BY-SA-3.0","CC0-1.0","Expat","FSFULLR","GPL-2","GPL-2+","Iconv-PD","Janik-permissive","Kuchling-PD","LGPL-2","LGPL-2+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","MPL-1.1","Mingw-PD","Plumb-PD","Unicode-DFS-2016","bzip2-1.0.6","cmph","old-glib-tests"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libglib2.0-data/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libglib2.0-data/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libglib2.0-data.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libglib2.0-data.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libglib2.0-data.list"}],"upstreams":[{"name":"glib2.0"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86469","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glib2.0","version":"2.80.0-6ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86469","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"risk":0.07050000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86469"},"relatedVulnerabilities":[{"id":"CVE-2026-86469","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","metrics":{"baseScore":5.3,"impactScore":4.3,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86469","cwe":"CWE-59","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-86469","date":"2026-10-08","epss":0.00141,"percentile":0.02941}],"urls":["https://access.redhat.com/security/cve/CVE-2026-86469","https://bugzilla.redhat.com/show_bug.cgi?id=2473839","https://gitlab.gnome.org/GNOME/glib/-/blob/main/gio/glocalfileoutputstream.c","https://gitlab.gnome.org/GNOME/glib/-/work_items/4044"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86469","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-41257","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-41257","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"risk":0.06849999999999999,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-41257"},"relatedVulnerabilities":[{"id":"CVE-2026-41257","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":6.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-41257","cwe":"CWE-190","type":"Secondary","source":"security-advisories@github.com"},{"cve":"CVE-2026-41257","cwe":"CWE-787","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-41257","date":"2026-10-08","epss":0.00137,"percentile":0.027}],"urls":["https://github.com/jqlang/jq/security/advisories/GHSA-4jm8-m363-4539"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-41257","description":"jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator forks), the doubling arithmetic overflows. The wrapped value is passed to realloc and then used for a memmove with attacker-influenced offsets."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-86138","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86138","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"risk":0.066,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86138"},"relatedVulnerabilities":[{"id":"CVE-2026-86138","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.9,"impactScore":5.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86138","cwe":"CWE-190","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-86138","date":"2026-10-08","epss":0.00132,"percentile":0.02383}],"urls":["https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86138","description":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."}]},{"artifact":{"id":"b65ce48fce2635c7","cpes":["cpe:2.3:a:dash:dash:0.5.12-6ubuntu5:*:*:*:*:*:*:*"],"name":"dash","purl":"pkg:deb/ubuntu/dash@0.5.12-6ubuntu5?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"0.5.12-6ubuntu5","language":"","licenses":["BSD-3-Clause","BSD-3-clause","GPL-2","GPL-2+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dash/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/dash/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dash.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.list"},{"path":"/var/lib/dpkg/info/dash.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postinst"},{"path":"/var/lib/dpkg/info/dash.postrm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.postrm"},{"path":"/var/lib/dpkg/info/dash.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/dash.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-102473","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"dash","version":"0.5.12-6ubuntu5"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-102473","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"risk":0.065,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-102473"},"relatedVulnerabilities":[{"id":"CVE-2026-102473","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-102473","cwe":"CWE-1333","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-102473","date":"2026-10-08","epss":0.0013,"percentile":0.02283}],"urls":["https://access.redhat.com/security/cve/CVE-2026-102473","https://bugzilla.redhat.com/show_bug.cgi?id=2543005"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-102473","description":"A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-95818","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-95818","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"risk":0.0645,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-95818"},"relatedVulnerabilities":[{"id":"CVE-2026-95818","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-95818","cwe":"CWE-121","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-95818","date":"2026-10-08","epss":0.00129,"percentile":0.02194}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0023"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-95818","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-0864","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-0864","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-0864"},"relatedVulnerabilities":[{"id":"CVE-2026-0864","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.1},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-0864","cwe":"CWE-74","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-0864","date":"2026-10-08","epss":0.00126,"percentile":0.02019}],"urls":["https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528","https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd","https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908","https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f","https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98","https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8","https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6","https://github.com/python/cpython/issues/143927","https://github.com/python/cpython/pull/151559","https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-0864","description":"When using the \"configparser\" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value."}]},{"artifact":{"id":"af95be31c1ad9110","cpes":["cpe:2.3:a:libpcre2-8-0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8-0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8_0:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2-8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2_8:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2-8-0:10.42-4ubuntu2.1:*:*:*:*:*:*:*","cpe:2.3:a:libpcre2:libpcre2_8_0:10.42-4ubuntu2.1:*:*:*:*:*:*:*"],"name":"libpcre2-8-0","purl":"pkg:deb/ubuntu/libpcre2-8-0@10.42-4ubuntu2.1?arch=amd64&distro=ubuntu-24.04&upstream=pcre2","type":"deb","version":"10.42-4ubuntu2.1","language":"","licenses":["BSD-2-clause","BSD-3-clause","BSD-3-clause-Cambridge","X11","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpcre2-8-0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libpcre2-8-0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libpcre2-8-0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"pcre2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-89161","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"pcre2","version":"10.42-4ubuntu2.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-89161","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"risk":0.063,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-89161"},"relatedVulnerabilities":[{"id":"CVE-2026-89161","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.4,"impactScore":5.9,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-89161","cwe":"CWE-590","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-89161","date":"2026-10-08","epss":0.00126,"percentile":0.02017}],"urls":["https://github.com/PCRE2Project/pcre2/pull/937","https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-89161","description":"In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur."}]},{"artifact":{"id":"f0ae564f6cc76e8b","cpes":["cpe:2.3:a:libc-bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc-bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc_bin:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc-bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*","cpe:2.3:a:libc:libc_bin:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc-bin","purl":"pkg:deb/ubuntu/libc-bin@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc-bin/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc-bin/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc-bin.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.list"},{"path":"/var/lib/dpkg/info/libc-bin.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.postinst"},{"path":"/var/lib/dpkg/info/libc-bin.triggers","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc-bin.triggers"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"a2811c097c883c6c","cpes":["cpe:2.3:a:libc6:libc6:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"libc6","purl":"pkg:deb/ubuntu/libc6@2.39-0ubuntu8.9?arch=amd64&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libc6/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libc6/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.conffiles","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libc6:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libc6:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"339e7c8af3fbd149","cpes":["cpe:2.3:a:locales:locales:2.39-0ubuntu8.9:*:*:*:*:*:*:*"],"name":"locales","purl":"pkg:deb/ubuntu/locales@2.39-0ubuntu8.9?arch=all&distro=ubuntu-24.04&upstream=glibc","type":"deb","version":"2.39-0ubuntu8.9","language":"","licenses":["sha256:d3c95b56fa33e28b57860580f0baf4e4f4de2a268a2b80f1d031a5191bade265"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/locales/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/locales/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/locales.config","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.config"},{"path":"/var/lib/dpkg/info/locales.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.list"},{"path":"/var/lib/dpkg/info/locales.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postinst"},{"path":"/var/lib/dpkg/info/locales.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.postrm"},{"path":"/var/lib/dpkg/info/locales.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.prerm"},{"path":"/var/lib/dpkg/info/locales.templates","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/locales.templates"}],"upstreams":[{"name":"glibc"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-86805","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"glibc","version":"2.39-0ubuntu8.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-86805","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"risk":0.062,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-86805"},"relatedVulnerabilities":[{"id":"CVE-2026-86805","cvss":[{"type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","metrics":{"baseScore":6.3,"impactScore":5.5,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-86805","cwe":"CWE-367","type":"Secondary","source":"3ff69d7a-14f2-4f67-a097-88dee7810d18"}],"epss":[{"cve":"CVE-2026-86805","date":"2026-10-08","epss":0.00124,"percentile":0.01887}],"urls":["https://sourceware.org/bugzilla/show_bug.cgi?id=34360","https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0022"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-86805","description":"A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.\n\nExploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by \"..\" traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-18503","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18503","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"risk":0.059500000000000004,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18503"},"relatedVulnerabilities":[{"id":"CVE-2026-18503","cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":2.4},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18503","cwe":"CWE-1176","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2026-18503","date":"2026-10-08","epss":0.00119,"percentile":0.0162}],"urls":["https://github.com/python/cpython/commit/063d4555c94ef412c731527dbf30193327f2ee82","https://github.com/python/cpython/commit/476fb09cdb0d73e645849d98c610e7e5697ce7c9","https://github.com/python/cpython/commit/89f29c760c02774b099ddd6863268eb13fa3946a","https://github.com/python/cpython/commit/b09a67a20c464f8288c9f9a6b9c7082a74560024","https://github.com/python/cpython/commit/b30c7fa9edd921a118f286e9f90f560777fa693b","https://github.com/python/cpython/commit/fd78b565d7c326f96ae903ab945b47f35d829cf4","https://github.com/python/cpython/issues/98820","https://github.com/python/cpython/pull/153694","https://mail.python.org/archives/list/security-announce@python.org/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503","description":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff()."}]},{"artifact":{"id":"bb3fa210c4617fe7","cpes":["cpe:2.3:a:libacl1:libacl1:2.3.2-1build1.1:*:*:*:*:*:*:*"],"name":"libacl1","purl":"pkg:deb/ubuntu/libacl1@2.3.2-1build1.1?arch=amd64&distro=ubuntu-24.04&upstream=acl","type":"deb","version":"2.3.2-1build1.1","language":"","licenses":["GPL-2","GPL-2+","LGPL-2+","LGPL-2.1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libacl1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libacl1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libacl1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libacl1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"acl"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-54370","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"acl","version":"2.3.2-1build1.1"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-54370","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"risk":0.05550000000000001,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-54370"},"relatedVulnerabilities":[{"id":"CVE-2026-54370","cvss":[{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":7.2},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"disclosure@vulncheck.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","metrics":{"baseScore":6.3,"impactScore":5.2,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-54370","cwe":"CWE-367","type":"Secondary","source":"disclosure@vulncheck.com"}],"epss":[{"cve":"CVE-2026-54370","date":"2026-10-08","epss":0.00111,"percentile":0.01222}],"urls":["https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5","https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1","https://www.vulncheck.com/advisories/acl-toctou-symlink-traversal-via-getfacl-setfacl-chacl"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-54370","description":"acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation."}]},{"artifact":{"id":"4b40fd420b47c163","cpes":["cpe:2.3:a:libpython3.12-minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_minimal:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-minimal","purl":"pkg:deb/ubuntu/libpython3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-minimal:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"dbe12549c4bf670f","cpes":["cpe:2.3:a:libpython3.12-stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12-stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12_stdlib:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12-stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:libpython3.12:libpython3.12_stdlib:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"libpython3.12-stdlib","purl":"pkg:deb/ubuntu/libpython3.12-stdlib@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpython3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpython3.12-stdlib/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpython3.12-stdlib:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"793834de357c34b2","cpes":["cpe:2.3:a:python3.12:python3.12:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12","purl":"pkg:deb/ubuntu/python3.12@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.list"},{"path":"/var/lib/dpkg/info/python3.12.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.postinst"},{"path":"/var/lib/dpkg/info/python3.12.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"f13475867b621878","cpes":["cpe:2.3:a:python3.12-minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12-minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12_minimal:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12-minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*","cpe:2.3:a:python3.12:python3.12_minimal:3.12.3-1ubuntu0.17:*:*:*:*:*:*:*"],"name":"python3.12-minimal","purl":"pkg:deb/ubuntu/python3.12-minimal@3.12.3-1ubuntu0.17?arch=amd64&distro=ubuntu-24.04&upstream=python3.12","type":"deb","version":"3.12.3-1ubuntu0.17","language":"","licenses":["sha256:f1cbf908e1daa8789b389fdcf17811ed36b675d736b39a103591399861350382"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/python3.12-minimal/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/python3.12-minimal/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/python3.12-minimal.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.list"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.postrm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.postrm"},{"path":"/var/lib/dpkg/info/python3.12-minimal.preinst","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.preinst"},{"path":"/var/lib/dpkg/info/python3.12-minimal.prerm","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/python3.12-minimal.prerm"}],"upstreams":[{"name":"python3.12"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-57177","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"python3.12","version":"3.12.3-1ubuntu0.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-57177","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"risk":0.054,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-57177"},"relatedVulnerabilities":[{"id":"CVE-2026-57177","cvss":[{"type":"Secondary","source":"security-advisories@github.com","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","metrics":{"baseScore":4.3,"impactScore":1.5,"exploitabilityScore":2.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-57177","cwe":"CWE-352","type":"Secondary","source":"security-advisories@github.com"}],"epss":[{"cve":"CVE-2026-57177","date":"2026-10-08","epss":0.00108,"percentile":0.01125}],"urls":["https://github.com/python-social-auth/social-core/security/advisories/GHSA-x7qq-23vw-7pfg"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-57177","description":"Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's LoginRadius identity. The issue affects only applications using the LoginRadius backend. The issue has been fixe in version 5.0.0 by enabling callback state validation for the LoginRadius backend."}]},{"artifact":{"id":"e2ab31589535b3e0","cpes":["cpe:2.3:a:patch:patch:2.7.6-7build3:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/ubuntu/patch@2.7.6-7build3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.7.6-7build3","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2019-20633","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"patch","version":"2.7.6-7build3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2019-20633","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2019-20633","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-20633","date":"2026-10-08","epss":0.01023,"percentile":0.62406}],"risk":0.05115,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2019-20633"},"relatedVulnerabilities":[{"id":"CVE-2019-20633","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2019-20633","cwe":"CWE-415","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2019-20633","date":"2026-10-08","epss":0.01023,"percentile":0.62406}],"urls":["https://savannah.gnu.org/bugs/index.php?56683"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2019-20633","description":"GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952."}]},{"artifact":{"id":"7ee9c92e46ca469e","cpes":["cpe:2.3:a:golang:x\\/sys:v0.20.0:*:*:*:*:*:*:*"],"name":"golang.org/x/sys","purl":"pkg:golang/golang.org/x/sys@v0.20.0","type":"go-module","version":"v0.20.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:Od9JTbYCk261bKm4M/mw7AklTlFYIa0bIp9BgSm1S8Y=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"0.44.0"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5024","versionConstraint":"<0.44.0 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/sys","version":"v0.20.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5024","fix":{"state":"fixed","versions":["0.44.0"],"available":[{"date":"2026-04-23","kind":"release","version":"0.44.0"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"risk":0.04976999999999999,"urls":["https://go.dev/cl/770080","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/78916","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."},"relatedVulnerabilities":[{"id":"CVE-2026-39824","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-39824","cwe":"CWE-190","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-39824","date":"2026-10-08","epss":0.00158,"percentile":0.0438}],"urls":["https://go.dev/cl/770080","https://go.dev/issue/78916","https://groups.google.com/g/golang-announce/c/6MMI8Lj-Atg","https://pkg.go.dev/vuln/GO-2026-5024"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-39824","description":"NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error."}]},{"artifact":{"id":"17317631a09f6a3f","cpes":["cpe:2.3:a:libsystemd0:libsystemd0:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libsystemd0","purl":"pkg:deb/ubuntu/libsystemd0@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libsystemd0/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libsystemd0/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libsystemd0:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"c37cad8d5a3a6548","cpes":["cpe:2.3:a:libudev1:libudev1:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"libudev1","purl":"pkg:deb/ubuntu/libudev1@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libudev1/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/libudev1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libudev1:amd64.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/libudev1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"817535dcd7b4fdf9","cpes":["cpe:2.3:a:systemd-standalone-sysusers:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone-sysusers:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone_sysusers:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone_sysusers:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd-standalone:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd_standalone:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd-standalone-sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*","cpe:2.3:a:systemd:systemd_standalone_sysusers:255.4-1ubuntu8.17:*:*:*:*:*:*:*"],"name":"systemd-standalone-sysusers","purl":"pkg:deb/ubuntu/systemd-standalone-sysusers@255.4-1ubuntu8.17?arch=amd64&distro=ubuntu-24.04&upstream=systemd","type":"deb","version":"255.4-1ubuntu8.17","language":"","licenses":["CC0-1.0","Expat","GPL-2","GPL-2+","LGPL-2.1","LGPL-2.1+","public-domain"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/systemd-standalone-sysusers/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/systemd-standalone-sysusers/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-standalone-sysusers.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/systemd-standalone-sysusers.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/systemd-standalone-sysusers.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/systemd-standalone-sysusers.list"}],"upstreams":[{"name":"systemd"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-40228","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"systemd","version":"255.4-1ubuntu8.17"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-40228","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"risk":0.0417,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-40228"},"relatedVulnerabilities":[{"id":"CVE-2026-40228","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","metrics":{"baseScore":2.9,"impactScore":1.5,"exploitabilityScore":1.5},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-40228","cwe":"CWE-669","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-40228","date":"2026-10-08","epss":0.00139,"percentile":0.02826}],"urls":["https://www.openwall.com/lists/oss-security/2026/04/08/1","http://www.openwall.com/lists/oss-security/2026/05/05/1"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-40228","description":"In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a \"logger -p emerg\" command is executed, if ForwardToWall=yes is set."}]},{"artifact":{"id":"b640c480c74193fe","cpes":["cpe:2.3:a:tar:tar:1.35\\+dfsg-3ubuntu0.4:*:*:*:*:*:*:*"],"name":"tar","purl":"pkg:deb/ubuntu/tar@1.35%2Bdfsg-3ubuntu0.4?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.35+dfsg-3ubuntu0.4","language":"","licenses":["GPL-2","GPL-2+","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/tar/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/tar/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/tar.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.list"},{"path":"/var/lib/dpkg/info/tar.postinst","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.postinst"},{"path":"/var/lib/dpkg/info/tar.prerm","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/tar.prerm"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-18477","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"tar","version":"1.35+dfsg-3ubuntu0.4"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-18477","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"risk":0.04,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-18477"},"relatedVulnerabilities":[{"id":"CVE-2026-18477","cvss":[{"type":"Secondary","source":"secalert@redhat.com","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","metrics":{"baseScore":4.4,"impactScore":3.6,"exploitabilityScore":0.8},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-18477","cwe":"CWE-367","type":"Secondary","source":"secalert@redhat.com"}],"epss":[{"cve":"CVE-2026-18477","date":"2026-10-08","epss":0.0008,"percentile":0.00144}],"urls":["https://access.redhat.com/errata/RHSA-2026:49361","https://access.redhat.com/errata/RHSA-2026:61581","https://access.redhat.com/errata/RHSA-2026:61586","https://access.redhat.com/errata/RHSA-2026:61783","https://access.redhat.com/errata/RHSA-2026:66018","https://access.redhat.com/errata/RHSA-2026:70390","https://access.redhat.com/security/cve/CVE-2026-18477","https://bugzilla.redhat.com/show_bug.cgi?id=2509735"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-18477","description":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}]},{"artifact":{"id":"50a5f90955be3d4b","cpes":["cpe:2.3:a:dirmngr:dirmngr:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"dirmngr","purl":"pkg:deb/ubuntu/dirmngr@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/dirmngr/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/dirmngr/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/dirmngr.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.list"},{"path":"/var/lib/dpkg/info/dirmngr.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postinst"},{"path":"/var/lib/dpkg/info/dirmngr.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.postrm"},{"path":"/var/lib/dpkg/info/dirmngr.preinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.preinst"},{"path":"/var/lib/dpkg/info/dirmngr.prerm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/dirmngr.prerm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"a4b63a4bf6a5b600","cpes":["cpe:2.3:a:gnupg:gnupg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg","purl":"pkg:deb/ubuntu/gnupg@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"b99f35328df2c1c9","cpes":["cpe:2.3:a:gnupg-l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_l10n:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_l10n:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-l10n","purl":"pkg:deb/ubuntu/gnupg-l10n@2.4.4-2ubuntu17.6?arch=all&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-l10n/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-l10n/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-l10n.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-l10n.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"312c3b72c37ce5e0","cpes":["cpe:2.3:a:gnupg-utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg-utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg_utils:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg-utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gnupg:gnupg_utils:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gnupg-utils","purl":"pkg:deb/ubuntu/gnupg-utils@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gnupg-utils/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gnupg-utils/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gnupg-utils.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gnupg-utils.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"111d86dc48f741d8","cpes":["cpe:2.3:a:gpg:gpg:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg","purl":"pkg:deb/ubuntu/gpg@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5315a0165ef4e458","cpes":["cpe:2.3:a:gpg-agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_agent:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_agent:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-agent","purl":"pkg:deb/ubuntu/gpg-agent@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-agent/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-agent/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.conffiles","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.conffiles","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-agent.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.list"},{"path":"/var/lib/dpkg/info/gpg-agent.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postinst"},{"path":"/var/lib/dpkg/info/gpg-agent.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-agent.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"5995b623e873af09","cpes":["cpe:2.3:a:gpg-wks-client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks-client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks_client:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg-wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg_wks:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg-wks-client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*","cpe:2.3:a:gpg:gpg_wks_client:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpg-wks-client","purl":"pkg:deb/ubuntu/gpg-wks-client@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpg-wks-client/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpg-wks-client/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpg-wks-client.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpg-wks-client.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"9ff230767a747dbe","cpes":["cpe:2.3:a:gpgconf:gpgconf:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgconf","purl":"pkg:deb/ubuntu/gpgconf@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgconf/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgconf/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgconf.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgconf.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"2062e3cd90405dfe","cpes":["cpe:2.3:a:gpgsm:gpgsm:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgsm","purl":"pkg:deb/ubuntu/gpgsm@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgsm/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/gpgsm/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgsm.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/gpgsm.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"db9250ad2fb3f819","cpes":["cpe:2.3:a:gpgv:gpgv:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"gpgv","purl":"pkg:deb/ubuntu/gpgv@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/gpgv/copyright","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/usr/share/doc/gpgv/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.md5sums","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/gpgv.list","layerID":"sha256:714dd50c4841aa84671262b2a74aa255feee9fbda2a95574122a9f88777c49a4","accessPath":"/var/lib/dpkg/info/gpgv.list"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"87b56c9afd975b01","cpes":["cpe:2.3:a:keyboxd:keyboxd:2.4.4-2ubuntu17.6:*:*:*:*:*:*:*"],"name":"keyboxd","purl":"pkg:deb/ubuntu/keyboxd@2.4.4-2ubuntu17.6?arch=amd64&distro=ubuntu-24.04&upstream=gnupg2","type":"deb","version":"2.4.4-2ubuntu17.6","language":"","licenses":["BSD-3-clause","CC0-1.0","Expat","GPL-2+","GPL-2.0","GPL-3","GPL-3+","LGPL-2.1","LGPL-2.1+","LGPL-3","LGPL-3+","RFC-Reference","TinySCHEME","permissive"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/keyboxd/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/keyboxd/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/keyboxd.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.list"},{"path":"/var/lib/dpkg/info/keyboxd.postinst","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postinst"},{"path":"/var/lib/dpkg/info/keyboxd.postrm","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/keyboxd.postrm"}],"upstreams":[{"name":"gnupg2"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-105712","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"gnupg2","version":"2.4.4-2ubuntu17.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-105712","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"risk":0.036899999999999995,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-105712"},"relatedVulnerabilities":[{"id":"CVE-2026-105712","cvss":[{"type":"Secondary","source":"cve@mitre.org","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","metrics":{"baseScore":3.6,"impactScore":2.6,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-105712","cwe":"CWE-61","type":"Secondary","source":"cve@mitre.org"}],"epss":[{"cve":"CVE-2026-105712","date":"2026-10-08","epss":0.00123,"percentile":0.01853}],"urls":["https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","https://static.dev.gnupg.org/T8159.html"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","description":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk."}]},{"artifact":{"id":"e2ab31589535b3e0","cpes":["cpe:2.3:a:patch:patch:2.7.6-7build3:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/ubuntu/patch@2.7.6-7build3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.7.6-7build3","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2021-45261","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"patch","version":"2.7.6-7build3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2021-45261","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2021-45261","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45261","date":"2026-10-08","epss":0.00705,"percentile":0.5191}],"risk":0.035250000000000004,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2021-45261"},"relatedVulnerabilities":[{"id":"CVE-2021-45261","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Primary","source":"nvd@nist.gov","vector":"AV:N/AC:M/Au:N/C:N/I:N/A:P","metrics":{"baseScore":4.3,"impactScore":2.9,"exploitabilityScore":8.6},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2021-45261","cwe":"CWE-763","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2021-45261","date":"2026-10-08","epss":0.00705,"percentile":0.5191}],"urls":["https://savannah.gnu.org/bugs/?61685"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2021-45261","description":"An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service."}]},{"artifact":{"id":"e2ab31589535b3e0","cpes":["cpe:2.3:a:patch:patch:2.7.6-7build3:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/ubuntu/patch@2.7.6-7build3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.7.6-7build3","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56288","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"patch","version":"2.7.6-7build3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56288","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56288","cwe":"CWE-476","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56288","date":"2026-10-08","epss":0.00115,"percentile":0.01423}],"risk":0.034499999999999996,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56288"},"relatedVulnerabilities":[{"id":"CVE-2026-56288","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56288","cwe":"CWE-476","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56288","date":"2026-10-08","epss":0.00115,"percentile":0.01423}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56288","https://cgit.git.savannah.gnu.org/cgit/patch.git/","https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=e6d6a4e021660679d7fc9150f981d4920f722313"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56288","description":"GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing.\nAn attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.\n\n\n\nThis issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313"}]},{"artifact":{"id":"e2ab31589535b3e0","cpes":["cpe:2.3:a:patch:patch:2.7.6-7build3:*:*:*:*:*:*:*"],"name":"patch","purl":"pkg:deb/ubuntu/patch@2.7.6-7build3?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.7.6-7build3","language":"","licenses":["sha256:8c70d7b0af209abe627c97cd21883931b891c820d0a4affcc10b789a23538a0d"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/patch/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/patch/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/patch.list","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/patch.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-56289","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"patch","version":"2.7.6-7build3"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-56289","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-56289","cwe":"CWE-835","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56289","date":"2026-10-08","epss":0.00115,"percentile":0.01423}],"risk":0.034499999999999996,"urls":[],"severity":"Low","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-56289"},"relatedVulnerabilities":[{"id":"CVE-2026-56289","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":4.6},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-56289","cwe":"CWE-835","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-56289","date":"2026-10-08","epss":0.00115,"percentile":0.01423}],"urls":["https://cert.pl/en/posts/2026/07/CVE-2026-56288","https://cgit.git.savannah.gnu.org/cgit/patch.git/","https://cgit.git.savannah.gnu.org/cgit/patch.git/commit/?id=faba04ef4f2b410257f76c1b9dc85e350929c4b9"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56289","description":"GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position.\nThis results in excessive CPU consumption and prevents the process from completing.\nAn attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.\n\n\n\nThis issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9"}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.25.8"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-4602","versionConstraint":"<1.25.8||>=1.26.0-0,<1.26.1 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-4602","fix":{"state":"fixed","versions":["1.25.8","1.26.1"],"available":[{"date":"2026-03-06","kind":"release","version":"1.25.8"},{"date":"2026-03-06","kind":"release","version":"1.26.1"}]},"cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"risk":0.03245,"urls":["https://go.dev/issue/77827","https://go.dev/cl/749480"],"severity":"Low","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened.\n\nThe impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."},"relatedVulnerabilities":[{"id":"CVE-2026-27139","cvss":[{"type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","metrics":{"baseScore":2.5,"impactScore":1.5,"exploitabilityScore":1.1},"version":"3.1","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-27139","cwe":"CWE-22","type":"Primary","source":"nvd@nist.gov"}],"epss":[{"cve":"CVE-2026-27139","date":"2026-10-08","epss":0.00118,"percentile":0.01593}],"urls":["https://go.dev/cl/749480","https://go.dev/issue/77827","https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk","https://pkg.go.dev/vuln/GO-2026-4602"],"severity":"Low","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-27139","description":"On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the filesystem without permitting reading or writing files outside the root."}]},{"artifact":{"id":"45238dd8c0d9c4b5","cpes":["cpe:2.3:a:jq:jq:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"jq","purl":"pkg:deb/ubuntu/jq@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/jq/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/jq/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.md5sums","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/jq.list","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/jq.list"}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-9403","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"risk":0.0108,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-9403"},"relatedVulnerabilities":[{"id":"CVE-2025-9403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well."}]},{"artifact":{"id":"a8a66caf33672ff8","cpes":["cpe:2.3:a:libjq1:libjq1:1.7.1-3ubuntu0.24.04.2:*:*:*:*:*:*:*"],"name":"libjq1","purl":"pkg:deb/ubuntu/libjq1@1.7.1-3ubuntu0.24.04.2?arch=amd64&distro=ubuntu-24.04&upstream=jq","type":"deb","version":"1.7.1-3ubuntu0.24.04.2","language":"","licenses":["CC-BY-3.0","Expat","GPL-2","GPL-2.0+","MIT"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libjq1/copyright","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/usr/share/doc/libjq1/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libjq1:amd64.md5sums","layerID":"sha256:e305f8f5396b46fa398957a09b187815632ecc6881afdf9c35643b00b2a956d5","accessPath":"/var/lib/dpkg/info/libjq1:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"jq"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2025-9403","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"jq","version":"1.7.1-3ubuntu0.24.04.2"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2025-9403","fix":{"state":"not-fixed","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"risk":0.0108,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2025-9403"},"relatedVulnerabilities":[{"id":"CVE-2025-9403","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","metrics":{"baseScore":5.5,"impactScore":3.6,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.9},"version":"4.0","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","metrics":{"baseScore":3.3,"impactScore":1.5,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cna@vuldb.com","vector":"AV:L/AC:L/Au:S/C:N/I:N/A:P","metrics":{"baseScore":1.7,"impactScore":2.9,"exploitabilityScore":3.2},"version":"2.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-9403","cwe":"CWE-617","type":"Secondary","source":"cna@vuldb.com"}],"epss":[{"cve":"CVE-2025-9403","date":"2026-10-08","epss":0.00216,"percentile":0.10999}],"urls":["https://drive.google.com/file/d/1r8m9PhU_rk-QPj6OMcs415FcvWPD-zJY/view?usp=sharing","https://github.com/jqlang/jq/issues/3393","https://vuldb.com/?ctiid.321239","https://vuldb.com/?id.321239","https://vuldb.com/?submit.633170"],"severity":"Medium","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-9403","description":"A vulnerability was determined in jqlang jq up to 1.6. Impacted is the function run_jq_tests of the file jq_test.c of the component JSON Parser. Executing manipulation can lead to reachable assertion. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Other versions might be affected as well."}]},{"artifact":{"id":"7dfcc129c4a7c553","cpes":["cpe:2.3:a:libxml2:libxml2:2.9.14\\+dfsg-1.3ubuntu3.9:*:*:*:*:*:*:*"],"name":"libxml2","purl":"pkg:deb/ubuntu/libxml2@2.9.14%2Bdfsg-1.3ubuntu3.9?arch=amd64&distro=ubuntu-24.04","type":"deb","version":"2.9.14+dfsg-1.3ubuntu3.9","language":"","licenses":["ISC","MIT-1"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libxml2/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libxml2/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libxml2:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libxml2:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[]},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"CVE-2026-11979","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libxml2","version":"2.9.14+dfsg-1.3ubuntu3.9"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-11979","fix":{"state":"wont-fix","versions":[]},"cvss":[],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-11979","date":"2026-10-08","epss":0.00148,"percentile":0.03516}],"risk":0.007400000000000001,"urls":[],"severity":"Negligible","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-11979"},"relatedVulnerabilities":[{"id":"CVE-2026-11979","cvss":[{"type":"Primary","source":"nvd@nist.gov","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","metrics":{"baseScore":7.8,"impactScore":5.9,"exploitabilityScore":1.9},"version":"3.1","vendorMetadata":{}},{"type":"Secondary","source":"cvd@cert.pl","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":1.8},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-11979","cwe":"CWE-121","type":"Secondary","source":"cvd@cert.pl"}],"epss":[{"cve":"CVE-2026-11979","date":"2026-10-08","epss":0.00148,"percentile":0.03516}],"urls":["https://cert.pl/en/posts/2026/06/CVE-2026-11979","https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e"],"severity":"High","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-11979","description":"libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking.\nBy supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame.\nSuccessful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.\n\nThis issue has been fixed in the commit c2e233fc.\n\nNOTE:\nThe maintainers of this project did not agree that this issue is a vulnerability and considered it a bug."}]},{"artifact":{"id":"01814745da17448f","cpes":["cpe:2.3:a:libpng16-16t64:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16-16t64:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16_16t64:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16-16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*","cpe:2.3:a:libpng16:libpng16_16t64:1.6.43-5ubuntu0.6:*:*:*:*:*:*:*"],"name":"libpng16-16t64","purl":"pkg:deb/ubuntu/libpng16-16t64@1.6.43-5ubuntu0.6?arch=amd64&distro=ubuntu-24.04&upstream=libpng1.6","type":"deb","version":"1.6.43-5ubuntu0.6","language":"","licenses":["Apache-2.0","BSD-3-clause","BSD-like-with-advertising-clause","GPL-2","GPL-2+","expat","libpng"],"locations":[{"path":"/var/lib/dpkg/status","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/status","annotations":{"evidence":"primary"}},{"path":"/usr/share/doc/libpng16-16t64/copyright","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/usr/share/doc/libpng16-16t64/copyright","annotations":{"evidence":"supporting"}},{"path":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/var/lib/dpkg/info/libpng16-16t64:amd64.md5sums","annotations":{"evidence":"supporting"}}],"upstreams":[{"name":"libpng1.6"}]},"matchDetails":[{"type":"exact-indirect-match","found":{"vulnerabilityID":"CVE-2026-46675","versionConstraint":"none (unknown)"},"matcher":"dpkg-matcher","searchedBy":{"distro":{"type":"ubuntu","version":"24.04"},"package":{"name":"libpng1.6","version":"1.6.43-5ubuntu0.6"},"namespace":"ubuntu:distro:ubuntu:24.04"}}],"vulnerability":{"id":"CVE-2026-46675","fix":{"state":"not-fixed","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Medium","namespace":"ubuntu:distro:ubuntu:24.04","advisories":[],"dataSource":"https://ubuntu.com/security/CVE-2026-46675"},"relatedVulnerabilities":[{"id":"CVE-2026-46675","cvss":[],"urls":[],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"nvd"}]},{"artifact":{"id":"1202e7b51088fcfe","cpes":["cpe:2.3:a:klauspost:compress:v1.17.7:*:*:*:*:*:*:*"],"name":"github.com/klauspost/compress","purl":"pkg:golang/github.com/klauspost/compress@v1.17.7","type":"go-module","version":"v1.17.7","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ehO88t2UGzQK66LMdE8tibEd1ErmzZjNEqWkjLAKQQg=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.18.7"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5841","versionConstraint":">=1.16.0,<1.18.7 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"github.com/klauspost/compress","version":"v1.17.7"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5841","fix":{"state":"fixed","versions":["1.18.7"],"available":[{"date":"2026-06-30","kind":"release","version":"1.18.7"}]},"cvss":[],"risk":0,"urls":["https://github.com/klauspost/compress/commit/8668e357e776d5152ed62f33c17f21b8690664fa"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://github.com/klauspost/compress/security/advisories/GHSA-259r-337f-4rfw","description":"Providing a specially crafted dictionary to s2.NewDict and using it to encode data can make the encoder read out of bounds."},"relatedVulnerabilities":[{"id":"GHSA-259r-337f-4rfw","cvss":[],"urls":[],"severity":"Unknown","namespace":"github:language:go","dataSource":"github"}]},{"artifact":{"id":"ce28d3c791c84ab4","cpes":["cpe:2.3:a:golang:crypto:v0.19.0:*:*:*:*:go:*:*","cpe:2.3:a:go:ssh:v0.19.0:*:*:*:*:go:*:*"],"name":"golang.org/x/crypto","purl":"pkg:golang/golang.org/x/crypto@v0.19.0","type":"go-module","version":"v0.19.0","language":"go","licenses":[],"metadata":{"h1Digest":"h1:ENy+Az/9Y1vSrlrvBSyna3PITt4tiZLf7sgCjZBX7Wo=","mainModule":"storj.io/uplink-c","architecture":"amd64","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-5932","versionConstraint":"none (unknown)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"golang.org/x/crypto","version":"v0.19.0"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-5932","fix":{"state":"","versions":[]},"cvss":[],"risk":0,"urls":[],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/issue/44226","description":"The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.\n\nIf you are required to interoperate with OpenPGP systems and need a maintained package, consider github.com/ProtonMail/go-crypto/openpgp which is a maintained fork that aims to be a drop-in replacement for this package."},"relatedVulnerabilities":[]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6599","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6599","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/839866","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression.\n\nWe now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-94448","cvss":[],"urls":["https://go.dev/cl/839866","https://go.dev/issue/81821","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6599"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94448","description":"When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6600","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6600","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/840925","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped.\n\nWe now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."},"relatedVulnerabilities":[{"id":"CVE-2026-97030","cvss":[],"urls":["https://go.dev/cl/840925","https://go.dev/issue/81823","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6600"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97030","description":"A trusted template author may have previously written a valid template wherein the use of the 'yield' keyword would not be correctly escaped. We now ensure that valid keyword uses are escaped and non-keyword uses are not escaped."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6603","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6603","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847185","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."},"relatedVulnerabilities":[{"id":"CVE-2026-78659","cvss":[],"urls":["https://go.dev/cl/847185","https://go.dev/cl/847314","https://go.dev/issue/81857","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6603"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78659","description":"When \"Trailer\" headers are sent by a client, the HTTP server internally uses the header values to populate the Request.Trailer map passed to the server handler. Because Request.Trailer is a map, each entry incurs memory overhead. For HTTP/2 servers, a malicious client can exploit this by sending a \"Trailer\" header that declares a large number of fields, causing the server to allocate a disproportionate amount of memory while bypassing Server.MaxHeaderValueCount and Server.MaxHeaderBytes limits. This exploit is not applicable for HTTP/1 servers, which do not support multiplexing a large number of requests over one TCP connection, and whose Server.MaxHeaderBytes are calculated differently."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6604","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6604","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847305","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."},"relatedVulnerabilities":[{"id":"CVE-2026-56857","cvss":[],"urls":["https://go.dev/cl/847305","https://go.dev/issue/81739","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6604"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56857","description":"On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target)."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6605","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6605","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847306","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."},"relatedVulnerabilities":[{"id":"CVE-2026-56866","cvss":[],"urls":["https://go.dev/cl/847306","https://go.dev/issue/81740","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6605"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-56866","description":"When http.Transport sends an HTTP/1 CONNECT request with a non-empty Request.Body, it writes the body directly to the connection without framing after the request headers. If the server rejects the CONNECT request with a non-2xx keep-alive response, Transport returns the connection to the idle pool. Because CONNECT requests do not have a request body, the server may interpret the trailing body bytes as a subsequent pipelined HTTP/1.1 request on the connection, leaving the pooled connection desynchronized and causing the next caller that reuses it to read the response to the injected request. In reverse proxies (including httputil.ReverseProxy) that forward CONNECT requests through a shared Transport, this can lead to cross-user response poisoning."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6607","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6607","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847312","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references.\n\nWe now reject these as malformed and curb the memory amplification vector as a result."},"relatedVulnerabilities":[{"id":"CVE-2026-97031","cvss":[],"urls":["https://go.dev/cl/847312","https://go.dev/issue/81855","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6607"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97031","description":"Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6608","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6608","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847307","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."},"relatedVulnerabilities":[{"id":"CVE-2026-94440","cvss":[],"urls":["https://go.dev/cl/847307","https://go.dev/issue/81741","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6608"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94440","description":"Parsing a multipart form can bypass memory limits and read an arbitrarily long line into memory when the remaining limit at the start of a part is less than 400 bytes."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6609","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6609","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847309","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."},"relatedVulnerabilities":[{"id":"CVE-2026-78667","cvss":[],"urls":["https://go.dev/cl/847309","https://go.dev/issue/81858","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6609"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78667","description":"When parsing a Range header containing a large number of small ranges, FileServer(FS), ServeContent, and ServeFile(FS) can consume an excessive amount of CPU."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6610","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6610","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/835145","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."},"relatedVulnerabilities":[{"id":"CVE-2026-78660","cvss":[],"urls":["https://go.dev/cl/835145","https://go.dev/cl/836385","https://go.dev/issue/81115","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6610"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78660","description":"Historically, we have been rather lax about malformed framing-related headers in our HTTP/2 implementation, as they cannot interfere with HTTP/2 framing. However, this makes it possible for our HTTP/2 implementation to forward responses containing such headers to an HTTP/1 client when acting as a reverse proxy. If the HTTP/1 client also does not behave strictly enough, this can result in response smuggling."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6611","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6611","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847186","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."},"relatedVulnerabilities":[{"id":"CVE-2026-78669","cvss":[],"urls":["https://go.dev/cl/847186","https://go.dev/cl/847308","https://go.dev/issue/81742","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6611"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78669","description":"A malicious HTTP/2 peer can cause excessive CPU consumption in the client or server by opening a large number of streams and then sending many small SETTINGS frames containing SETTINGS_INITIAL_WINDOW_SIZE values."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6612","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6612","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847187","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."},"relatedVulnerabilities":[{"id":"CVE-2026-78663","cvss":[],"urls":["https://go.dev/cl/847187","https://go.dev/cl/847310","https://go.dev/issue/81743","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6612"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-78663","description":"The HTTP/2 server can refund connection-level flow control twice for the same data: Once when a client resets a stream (refunding data for any sent-but-unread portion of the stream), and again when a request handler reads the buffered data. A malicious client can exploit this to bypass the configured connection-level flow control limit (MaxReceiveBufferPerConnection). Total buffered data is still limited by the concurrent stream limit and stream-level flow control."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6613","versionConstraint":"<1.26.9||>=1.27.0-0,<1.27.2 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6613","fix":{"state":"fixed","versions":["1.26.9","1.27.2"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"},{"date":"2026-10-08","kind":"release","version":"1.27.2"}]},"cvss":[],"risk":0,"urls":["https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847311","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP.\n\nThe impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."},"relatedVulnerabilities":[{"id":"CVE-2026-94439","cvss":[],"urls":["https://go.dev/cl/847311","https://go.dev/issue/81744","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://pkg.go.dev/vuln/GO-2026-6613"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-94439","description":"When an HTTP server handler sends a 2xx response to an HTTP/1 CONNECT request and returns without hijacking the connection, the server improperly continues to read and serve requests from the connection. Since a 2xx response to an HTTP/1 CONNECT converts the connection into a tunnel, the server should not treat the connection as continuing to contain HTTP. The impact of this misbehavior is mostly limited to potential request smuggling, where an intermediate proxy considers the data on the connection to be tunneled and the server considers it to be HTTP."}]},{"artifact":{"id":"1307bb95cf161605","cpes":["cpe:2.3:a:golang:go:1.24.9:-:*:*:*:*:*:*"],"name":"stdlib","purl":"pkg:golang/stdlib@1.24.9","type":"go-module","version":"go1.24.9","language":"go","licenses":["BSD-3-Clause"],"metadata":{"architecture":"","goCompiledVersion":"go1.24.9"},"locations":[{"path":"/app/duplicati/storj_uplink.so","layerID":"sha256:6104365530550b2c12a8a0965ed62718b304ae11cfa6ab7f681838be9cce45f9","accessPath":"/app/duplicati/storj_uplink.so","annotations":{"evidence":"primary"}}],"upstreams":[],"metadataType":"GolangBinMetadata"},"matchDetails":[{"fix":{"suggestedVersion":"1.26.9"},"type":"exact-direct-match","found":{"vulnerabilityID":"GO-2026-6617","versionConstraint":"<1.26.9 (go)"},"matcher":"go-module-matcher","searchedBy":{"package":{"name":"stdlib","version":"go1.24.9"},"language":"go","namespace":"govulndb:language:go"}}],"vulnerability":{"id":"GO-2026-6617","fix":{"state":"fixed","versions":["1.26.9"],"available":[{"date":"2026-10-08","kind":"release","version":"1.26.9"}]},"cvss":[],"risk":0,"urls":["https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs"],"severity":"Unknown","namespace":"govulndb:language:go","advisories":[],"dataSource":"https://go.dev/cl/847188","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."},"relatedVulnerabilities":[{"id":"CVE-2026-97032","cvss":[],"urls":["https://go.dev/cl/847188","https://go.dev/cl/847313","https://go.dev/issue/81867","https://groups.google.com/g/golang-announce/c/U2fTuyDJznI","https://groups.google.com/g/golang-announce/c/ZPwCyRUuGBs","https://pkg.go.dev/vuln/GO-2026-6617"],"severity":"Unknown","namespace":"nvd:cpe","dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-97032","description":"HTTP/2 servers could end up crashing due to inadvertently modifying its HPACK encoder concurrently. This happens because the server modifies the HPACK encoder from two goroutines without synchronization: one uses the encoder to encode a HEADERS frame as part of a response sent to a client and the other modifies the encoder's table size when handling a SETTINGS frame containing SETTINGS_HEADER_TABLE_SIZE that a client sends. A malicious client can repeatedly send a request while changing the header table size to crash the server."}]}],"grade":"F","score":"0.00","as_of":"2026-10-10T02:46:38.577Z","grype_db_version":"2026-10-09T06:32:32.000Z"}